PHP SOAP extension use-after-free in SOAP_GLOBAL(ref_map) via apache:Map duplicate-key insertion (CVSS 9.5, pre-auth, all 8.x, fixed 2026-05-07)
cve · CVE-2026-6722
Coverage timeline
4
first 2026-05-11 → last 2026-05-17
Briefs
2
2 distinct
Sources cited
875
267 hosts
Sections touched
4
action_items, deep_dive, trending_vulns
Co-occurring entities
3
see Related entities below
Story timeline
- 2026-05-17CTI Weekly Summary — 2026-W20 (May 11 – May 17, 2026)
- 2026-05-11CTI Daily Brief — 2026-05-11
- 2026-05-11CTI Daily Brief — 2026-05-11
- 2026-05-11CTI Daily Brief — 2026-05-11
Where this entity is cited
- trending_vulns1
- deep_dive1
- action_items1
- weekly_summary1
Source distribution
- thehackernews.com93 (11%)
- bleepingcomputer.com74 (8%)
- securityweek.com43 (5%)
- github.com27 (3%)
- helpnetsecurity.com27 (3%)
- security-hub.ncsc.admin.ch25 (3%)
- microsoft.com14 (2%)
- msrc.microsoft.com14 (2%)
- other558 (64%)
Related entities
- PHP SOAP companion to CVE-2026-6722; patched 2026-05-08
- PHP SOAP companion to CVE-2026-6722; patched 2026-05-08
- Škoda Auto Deutschland online-shop breach exposes customer PII and password hashes; logging gap prevents exfiltration confirmation (2026-05-11)
External references
All cited sources (875)
- github.comprimaryfooterPHP GHSA-85c2-q967-79q5https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5
- github.comprimaryinlineGHSA-m33r-qmcv-p97qhttps://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q
- github.comprimaryinlineGHSA-hmxp-6pc4-f3vvhttps://github.com/php/php-src/security/advisories/GHSA-hmxp-6pc4-f3vv
- github.comprimaryinlineBedrock Safeguard decryptorhttps://github.com/Bedrock-Safeguard/gentlemen-decryptor
- github.comprimaryinlineGitHub release v2.5.42https://github.com/MISP/MISP/releases/tag/v2.5.42
- github.comprimaryinlineTanStack Router GHSA-g7cv-rxg3-hmpxhttps://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx
- github.comprimaryinlineResearcher write-up (V4bel), 2026-05-07https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md
- github.comprimaryinlineGitHub Security Advisory GHSA-679G-PP8V-JVG4https://github.com/advisories/GHSA-679G-PP8V-JVG4
- github.comprimaryinlineGitHub Security Advisory GHSA-834x-pvxg-xh58https://github.com/advisories/GHSA-834x-pvxg-xh58
- github.comprimaryinlineGitHub Security Advisory GHSA-fwfp-h68w-2hcrhttps://github.com/advisories/GHSA-fwfp-h68w-2hcr
- github.comprimaryinlineGitHub Advisory GHSA-fxrh-cwjh-m33vhttps://github.com/advisories/GHSA-fxrh-cwjh-m33v
- github.comprimaryinlineGitHub GHSA-gcgv-v5gf-c543https://github.com/advisories/GHSA-gcgv-v5gf-c543
- github.comprimaryinlineGitHub Security Advisory GHSA-h7wj-m45x-884xhttps://github.com/advisories/GHSA-h7wj-m45x-884x
- github.comprimaryinlineGitHub Advisory GHSA-jxfc-8wcq-xxcghttps://github.com/advisories/GHSA-jxfc-8wcq-xxcg
- github.comprimaryinlineGitHub Advisory GHSA-v4p8-mg3p-g94ghttps://github.com/advisories/GHSA-v4p8-mg3p-g94g
- github.comprimaryinlineGitHub Security Advisory GHSA-w52v-v783-gw97https://github.com/advisories/GHSA-w52v-v783-gw97
- github.comprimaryinlineGitHub Security Advisory GHSA-f75j-4cw6-rmx4https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4
- github.comprimaryinlineMandiant Vulnerability Disclosures MNDT-2026-0009https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0009.md
- github.comprimaryinlineGitHub GHSA-2ww3-72rp-wpp4https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-2ww3-72rp-wpp4
- github.comprimaryinlineGitHub GHSA-xjw9-4gw8-4rqxhttps://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx
- github.comprimaryinlinen8n GHSA-q5f4-99jv-pgg5, 2026-05-18https://github.com/n8n-io/n8n/security/advisories/GHSA-q5f4-99jv-pgg5
- github.comprimaryinlineGitHub Security Advisory GHSA-c9j4-9m59-847whttps://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
- github.comprimaryinlinePortainer GHSA-rrmm-9v76-h3p4https://github.com/portainer/portainer/security/advisories/GHSA-rrmm-9v76-h3p4
- github.comprimaryinlineGHSA-4j6x-2764-m8ghhttps://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh
- github.comprimaryinlineSUSE Rancher GHSA-mhc6-2gfq-xx62https://github.com/rancher/rancher/security/advisories/GHSA-mhc6-2gfq-xx62
- github.comprimaryinlineGHSA-vx8h-4prv-g744https://github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744
- github.comprimaryinlineGitHub Security Advisory GHSA-c9ph-gxww-7744, 2026-04-29https://github.com/thymeleaf/thymeleaf/security/advisories/GHSA-c9ph-gxww-7744
- 9to5mac.cominline9to5Machttps://9to5mac.com/2026/06/18/new-unpatchable-exploit-targets-apple-devices-with-a12-and-a13-chips/
- about.fb.cominlineMeta — Fighting spyware updatehttps://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/
- access.redhat.cominlineRed Hat CVE-2022-0492https://access.redhat.com/security/cve/cve-2022-0492
- access.redhat.cominlineRed Hat RHSB-2026-003https://access.redhat.com/security/vulnerabilities/RHSB-2026-003
- acronis.cominlineAcronis TRUhttps://www.acronis.com/en/tru/posts/from-emerging-threat-to-top-tier-ransomware-as-a-service-the-evolution-of-inc-ransomware/
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0158, 2026-05-15https://advisories.ncsc.nl/advisory?id=NCSC-2026-0158
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0159, 2026-05-15https://advisories.ncsc.nl/advisory?id=NCSC-2026-0159
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0168https://advisories.ncsc.nl/advisory?id=NCSC-2026-0168
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0171https://advisories.ncsc.nl/advisory?id=NCSC-2026-0171
- advisories.ncsc.nlinlineNCSC-NL advisory NCSC-2026-0179https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0185https://advisories.ncsc.nl/advisory?id=NCSC-2026-0185
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0189https://advisories.ncsc.nl/advisory?id=NCSC-2026-0189
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0162, 2026-05-15https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0162.json
- advisory.splunk.cominlineSplunk PSIRT SVD-2026-0603https://advisory.splunk.com/advisories/SVD-2026-0603
- aikido.devinlineAikido, 2026-05-21https://www.aikido.dev/blog/google-api-keys-deletion
- aikido.devinlineAikido Securityhttps://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys
- aikido.devinlineAikido Securityhttps://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm
- aikido.devinlineAikido, 2026-05-23https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer
- akamai.cominlineAkamai Security Research — Incomplete Patch APT28 CVE-2026-32202https://www.akamai.com/blog/security-research/incomplete-patch-apt28s-zero-day-cve-2026-32202
- almalinux.orginlineAlmaLinux bloghttps://almalinux.org/blog/2026-05-07-dirty-frag/
- amd.cominlineAMD Product Security AMD-SB-7052, 2026-05-12https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html
- appleinsider.cominlineApple Insiderhttps://appleinsider.com/articles/26/06/18/a12-a13-apple-devices-face-an-unpatchable-securerom-vulnerability
- arcticwolf.cominlineArctic Wolfhttps://arcticwolf.com/resources/blog/active-fortibleed-campaign-impacting-fortinet-devices-across-194-countries/
- arcticwolf.cominlineArctic Wolf, 2026-06-11https://arcticwolf.com/resources/blog/arctic-wolf-observes-increase-in-palo-alto-networks-globalprotect-authentication-bypass-exploitation-via-cve-2026-0257/
- arcticwolf.cominlineArctic Wolf — EKZ Infostealer campaignhttps://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/
- arcticwolf.cominlineArctic Wolfhttps://arcticwolf.com/resources/blog/smash-and-grab-aggressive-akira-campaign-targets-sonicwall-vpns/
- arista.cominlineArista, 2026-06-09https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137
- arxiv.orginlinearXiv, 2026-06-02https://arxiv.org/abs/2606.03811
- atos.netinlineAtos TRC, 2026-04-17https://atos.net/en/lp/cybershield/making-vulnerable-drivers-exploitable-without-hardware-the-byovd-perspective
- attack.mitre.orginlineT1021.004https://attack.mitre.org/techniques/T1021/004/
- attack.mitre.orginlineT1036https://attack.mitre.org/techniques/T1036/
- attack.mitre.orginlineT1041 Exfiltration Over C2 Channelhttps://attack.mitre.org/techniques/T1041/
- attack.mitre.orginlineT1133https://attack.mitre.org/techniques/T1133/
- attack.mitre.orginlineT1190https://attack.mitre.org/techniques/T1190/
- attack.mitre.orginlineT1195.002 Compromise Software Supply Chainhttps://attack.mitre.org/techniques/T1195/002/
- attack.mitre.orginline`T1485`https://attack.mitre.org/techniques/T1485/
- attack.mitre.orginlineT1486 Data Encrypted for Impacthttps://attack.mitre.org/techniques/T1486/
- attack.mitre.orginlineT1552.001 Credentials In Fileshttps://attack.mitre.org/techniques/T1552/001/
- attack.mitre.orginlineT1562.004https://attack.mitre.org/techniques/T1562/004/
- badhost.orginlineX41 / badhost.orghttps://badhost.org/
- bankinfosecurity.cominlineBankInfoSecurity, 2026-05-11https://www.bankinfosecurity.com/tables-turned-gentlemen-ransomware-group-suffers-data-leak-a-31654
- bishopfox.cominlineBishop Fox — CVE-2026-42208 technical analysishttps://bishopfox.com/blog/cve-2026-42208-pre-authentication-sql-injection-in-litellm-proxy
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/linux/exploit-released-for-new-pintheft-arch-linux-root-escalation-flaw/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/
- bleepingcomputer.cominlineBleepingComputer — June Patch Tuesdayhttps://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/
- bleepingcomputer.cominlineBleepingComputer — MiniPlasma zero-day PoChttps://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-26https://www.bleepingcomputer.com/news/security/7-eleven-data-breach-exposes-personal-information-of-185-000-people/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-24https://www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-21https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/
- bleepingcomputer.cominlineBleepingComputer — Charter confirmshttps://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-19https://www.bleepingcomputer.com/news/security/cisa-warns-fortinet-users-to-secure-devices-after-fortibleed-leak/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/
- bleepingcomputer.cominlineBleepingComputer — Kirkihttps://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-06https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/dashlane-password-manager-users-locked-out-by-brute-force-attacks/
- bleepingcomputer.cominlineBleepingComputer (2026-05-22)https://www.bleepingcomputer.com/news/security/drupal-critical-sql-injection-flaw-now-targeted-in-attacks/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-19https://www.bleepingcomputer.com/news/security/exploit-available-for-new-dirtydecrypt-linux-root-escalation-flaw/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/fbi-warns-of-fake-fifa-websites-running-world-cup-fraud-schemes/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-22https://www.bleepingcomputer.com/news/security/fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials/
- bleepingcomputer.cominlineBleepingComputer — first coveragehttps://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-13https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-rce-flaws-in-fortisandbox-and-fortiauthenticator/
- bleepingcomputer.cominlineBleepingComputer — Funnel Builder skimmerhttps://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-24https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/github-announces-npm-security-changes-to-tackle-supply-chain-attacks/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-20https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-18https://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/hackers-bypass-sonicwall-vpn-mfa-due-to-incomplete-patching/
- bleepingcomputer.cominlineBleepingComputer — Burst Statisticshttps://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/
- bleepingcomputer.cominlineBleepingComputer — Instructure Canvas data breachhttps://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-07https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-epmm-flaw-exploited-in-zero-day-attacks/
- bleepingcomputer.cominlineBleepingComputer — Kyushu Electrichttps://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-19https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-08https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-19https://www.bleepingcomputer.com/news/security/microsoft-self-service-password-reset-abused-in-azure-data-theft-attacks/
- bleepingcomputer.cominlineBleepingComputer — IronWormhttps://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-prinz-eugen-ransomware-prioritizes-recent-files-for-encryption/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-16https://www.bleepingcomputer.com/news/security/new-rokarolla-android-malware-targets-217-banking-crypto-apps/
- bleepingcomputer.cominlineBleepingComputer — Nintendo/TinyPulsehttps://www.bleepingcomputer.com/news/security/nintendo-confirms-data-stolen-in-webmd-subsidiary-cyberattack/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-11https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/over-400-arch-linux-packages-compromised-to-push-rootkit-infostealer/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-15https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-16https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-09https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/shapedplugin-update-flow-hacked-to-infect-wordpress-sites/
- bleepingcomputer.cominlineBleepingComputer — Polyfill.iohttps://www.bleepingcomputer.com/news/security/suspicious-polyfill-login-prompts-pop-up-on-toshiba-muji-websites/
- bleepingcomputer.cominlineBleepingComputer — Texas Parkshttps://www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/
- bleepingcomputer.cominlineBleepingComputer — The Gentlemen + SystemBC, 2026-04-20https://www.bleepingcomputer.com/news/security/the-gentlemen-ransomware-now-uses-systembc-for-bot-powered-attacks/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-04https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-17https://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/ukrainian-national-pleads-guilty-to-role-in-conti-ransomware-operation/
- bleepingcomputer.cominlineBleepingComputer — Vimeo Anodothttps://www.bleepingcomputer.com/news/security/video-service-vimeo-confirms-anodot-breach-exposed-user-data/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/whatsapp-says-it-disrupted-new-nso-spyware-phishing-attacks/
- bleepingcomputer.cominlineBleepingComputer — Windows BitLocker zero-day PoChttps://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-16https://www.bleepingcomputer.com/news/security/windows-version-of-sprysocks-linux-malware-used-to-attack-govt-orgs/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/wordpress-malware-campaign-hides-payloads-in-steam-profiles/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/wp-maps-pro-bug-exploited-to-create-admin-accounts-on-wordpress-sites/
- blog.ammaraskar.cominlineAmmar Askarhttps://blog.ammaraskar.com/github-token-stealing/
- blog.calif.ioinlineCalif/Codex — HTTP/2 Bomb disclosurehttps://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
- blog.calif.ioinlineCalif.iohttps://blog.calif.io/p/squidbleed-cve-2026-47729
- blog.checkpoint.cominlineCheck Point Research — AI Threat Landscapehttps://blog.checkpoint.com/research/ai-attacks-are-no-longer-experimental-key-findings-from-the-march-april-2026-ai-threat-landscape/
- blog.checkpoint.cominlineCheck Point Research, 2026-05-08https://blog.checkpoint.com/research/cyber-threats-spike-in-april-2026-as-ransomware-expands-and-attack-volumes-climb-after-short-lived-moderation/
- blog.checkpoint.cominlineCheck Point Blog — fewer groups, higher impacthttps://blog.checkpoint.com/research/q1-2026-ransomware-report-fewer-groups-higher-impact/
- blog.checkpoint.cominlineCheck Point bloghttps://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk
- blog.checkpoint.cominlineCheck Point advisoryhttps://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/
- blog.daemon-tools.ccinlineDisc Soft Limited security incident noticehttps://blog.daemon-tools.cc/post/security-incident
- blog.exodusintel.cominlineExodus Intelligence write-uphttps://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/
- blog.fox-it.cominlineFox-IT, 2026-05-22https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/
- blog.gitea.cominlineGitea release noteshttps://blog.gitea.com/release-of-1.26.3-and-1.26.4
- blog.googleinlineGooglehttps://blog.google/innovation-and-ai/technology/safety-security/combatting-ai-scams/
- blog.litespeedtech.cominlineLiteSpeedhttps://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/
- blog.litespeedtech.cominlineLiteSpeed security updatehttps://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/
- blog.packagist.cominlinePackagist blog, 2026-05-13https://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/
- blog.qualys.cominlineQualys TRU on CVE-2026-46333https://blog.qualys.com/vulnerabilities-threat-research/2026/05/20/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path
- blog.sekoia.ioinlineSekoia TDRhttps://blog.sekoia.io/apt28-an-evolution-of-tradecraft/
- blog.sekoia.ioinlineSekoia — ErrTraffichttps://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/
- blog.talosintelligence.cominlineCisco Talos — DICOM / Orthanc heap analysishttps://blog.talosintelligence.com/dicom-pydicom-gdcm-and-orthanc-a-technical-tour-of-what-really-happens-in-the-heap/
- blog.talosintelligence.cominlineCisco Talos, 2026-05-19https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem/
- blog.talosintelligence.cominlineCisco Talos UAT-8616https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/
- blog.talosintelligence.cominlineCisco Talos — UAT-8302https://blog.talosintelligence.com/uat-8302/
- blog.talosintelligence.cominlineCisco Talos — UAT-8616https://blog.talosintelligence.com/uat-8616-sd-wan/
- blog.xlab.qianxin.cominlineQiAnXin XLab, 2026-06-17https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/
- blog.xlab.qianxin.cominlineXLab Qianxin, 2026-05-21https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/
- blogs.microsoft.cominlineMicrosoft On the Issues — DCU legal action, 2026-05-19https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/
- broadcom.cominlineBroadcom/Symantec protection bulletinhttps://www.broadcom.com/support/security-center/protection-bulletin/backdoor-mistic-new-backdoor-may-be-linked-to-ransomware-access-broker
- bsi.bund.deinlineBSI advisory 2026-05-07https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-211476-1032.html
- ccb.belgium.beinlineCCB Belgium, 2026-05-08https://ccb.belgium.be/advisories/warning-dirty-frag-new-linux-local-privilege-escalation-vulnerability-was-disclosed
- ccb.belgium.beinlineCCB Belgiumhttps://ccb.belgium.be/advisories/warning-fortinet-addresses-critical-command-injection-vulnerability-fortisandbox-patch
- ccb.belgium.beinlineCCB Belgium, 2026-05-20https://ccb.belgium.be/advisories/warning-nlnet-labs-has-addressed-multiple-vulnerabilities-unbound-dns-resolver-could
- ccb.belgium.beinlineCCB Belgium — Patch Immediatelyhttps://ccb.belgium.be/advisories/warning-two-critical-vulnerabilities-portainer-allow-full-host-takeover-patch
- cert.europa.euinlineCERT-EU 2026-005https://cert.europa.eu/publications/security-advisories/2026-005/
- cert.europa.euinlineCERT-EU Critical Advisory 2026-006https://cert.europa.eu/publications/security-advisories/2026-006/
- cert.europa.euinlineCERT-EU, 2026-06-10https://cert.europa.eu/publications/security-advisories/2026-007/
- cert.europa.euinlineCERT-EU 2026-008, 2026-06-10https://cert.europa.eu/publications/security-advisories/2026-008/
- cert.plinlineCERT Polskahttps://cert.pl/en/posts/2026/05/CVE-2026-42096/
- cert.plinlineCERT-PL, 2026-05-15https://cert.pl/en/posts/2026/05/CVE-2026-7182/
- cert.plinlineCERT Polska, 2026-05-25https://cert.pl/en/posts/2026/05/CVE-2026-9058/
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0543, 2026-05-07https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0543/
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0552, 2026-05-07https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0552/
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0576, 2026-05-13https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0576/
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0651https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0651/
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0652https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0652/
- checkmarx.cominlineCheckmarx, 2026-05-12https://checkmarx.com/blog/ongoing-security-updates/
- chromereleases.googleblog.cominlineGoogle Chrome Releaseshttps://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html
- chromereleases.googleblog.cominlineChrome, 2026-06-08https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
- cisa.govinlineCISA KEV cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
- cisa.govinlineCISA KEV alert, 2026-05-21https://www.cisa.gov/news-events/alerts/2026/05/21/cisa-adds-two-known-exploited-vulnerabilities-catalog
- cisa.govinlineCISAhttps://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog
- cisa.govinlineCISA KEV alerthttps://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog
- cisa.govinlineCISA — Adds one Known Exploited Vulnerability to Catalog, 2026-06-16https://www.cisa.gov/news-events/alerts/2026/06/16/cisa-adds-one-known-exploited-vulnerability-catalog
- cisa.govinlineCISA, 2026-06-18https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
- cisa.govinlineCISA ED-26-03https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems
- cisa.govinlineCISA ICS-CERT ICSA-26-167-03https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-03
- cisa.govinlineCISA ICS-CERT ICSA-26-167-05https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05
- cisa.govinlineCISA ICS advisory ICSA-26-169-01https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-01
- cloud.google.cominlineGTIG AI Threat Tracker May 2026https://cloud.google.com/blog/topics/threat-intelligence/ai-threat-tracker-may-2026/
- cloud.google.cominlineGoogle Cloud Threat Intelligence — AI vulnerability exploitation initial access, 2026-05-11https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access
- cloud.google.cominlineGoogle Cloud / GTIG — BlackFile vishing-extortion operationhttps://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation
- cloud.google.cominlineGoogle Threat Intelligence Group, 2026-05-15https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/
- cloud.google.cominlineGoogle Threat Intelligence Group, 2026-05-25https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/
- cloud.google.cominlineGoogle Threat Intelligence Grouphttps://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/
- cloud.google.cominlineGoogle Cloud / Mandiant M-Trends 2026, 2026-03-23https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
- cloud.google.cominlineGoogle GTIGhttps://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research
- cloud.google.cominlineGoogle GTIGhttps://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
- cloud.google.cominlineGoogle GTIGhttps://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/
- cloud.google.cominlineMandiant / Google Cloud GTIGhttps://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/
- cloud.google.cominlineMandiant — UNC6692https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware
- cnil.frinlineCNIL — €5M IQVIA finehttps://www.cnil.fr/en/health-data-fine-5-million-euros-against-iqvia
- coveware.cominlineCoveware, 2026-02-02https://www.coveware.com/blog/2026/2/2/nitrogen-ransomware-esxi-malware-has-a-bug
- crowdstrike.cominlineCrowdStrike 2026 Technology Threat Landscape Reporthttps://www.crowdstrike.com/en-us/blog/crowdstrike-2026-technology-threat-landscape-report/
- crowdstrike.cominlineCrowdStrike Counter Adversary Operationshttps://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/
- cryptotimes.ioinlineCryptoTimes, 2026-05-17https://www.cryptotimes.io/2026/05/17/10-8-million-drained-inside-the-thorchain-exploit-that-froze-cross-chain-defi-for-13-hours/
- csoonline.cominlineCSO Online, 2026-05-14https://www.csoonline.com/article/4171926/expired-domain-leads-to-supply-chain-attack-on-node-ipc-npm-package.html
- csoonline.cominlineCSO Online, 2026-05-20https://www.csoonline.com/article/4175329/drupal-admins-rushing-to-patch-maximum-severity-sql-injection-vulnerability.html
- csoonline.cominlineCSO Onlinehttps://www.csoonline.com/article/4189132/be-on-the-lookout-for-mistic-a-new-backdoor-used-by-ransomware-broker.html
- cve.threatint.euinlineTHREATINT CVE recordhttps://cve.threatint.eu/CVE/CVE-2026-44825
- cyber.gc.cainlineCanadian Centre for Cyber Securityhttps://www.cyber.gc.ca/en/guidance/cyber-threat-bulletin-fifa-world-cup-2026tm
- cyber.gouv.frinlineANSSIhttps://cyber.gouv.fr/en/publications/jointly-led-international-publications/declaration-of-the-g7-cybersecurity-working-group/
- cyberattaque.orginlineCyberattaque.org, 2026-06-16https://www.cyberattaque.org/g7-devian-plusieurs-sites-publics-de-haute-savoie-cibles-par-des-cyberattaques/
- cyberinsider.cominlineCyberInsider, 2026-05-26https://cyberinsider.com/7-eleven-data-breach-exposes-personal-information-of-185000-applicants/
- cyberinsider.cominlineCyberInsider, 2026-05-23https://cyberinsider.com/charter-communications-confirms-data-breach-as-hackers-threaten-leak-of-42-million-records/
- cyberkendra.cominlineCyberKendra — JDownloader malicious installershttps://www.cyberkendra.com/2026/05/jdownloader-website-hacked-malicious.html
- cyberscoop.cominlineCyberScoophttps://cyberscoop.com/blackfile-data-theft-extortion-retail-unit-42-rh-isac/
- cyberscoop.cominlineCyberScoophttps://cyberscoop.com/conti-ransomware-member-ukrainian-lytvynenko-guilty/
- cyberscoop.cominlineCyberScoophttps://cyberscoop.com/fbi-phishing-kali365-microsoft365-access-tokens/
- cyberscoop.cominlineCyberScoophttps://cyberscoop.com/meta-contempt-complaint-nso-group-spyware/
- cybersecuritydive.cominlineCybersecurity Divehttps://www.cybersecuritydive.com/news/iran-cyberattacks-espionage-us-israel-uae/820990/
- cybersecuritydive.cominlineCybersecurity Divehttps://www.cybersecuritydive.com/news/patch-bypass-hackers-exploit-flaw-sonicwall/820600/
- cybersecuritydive.cominlineCybersecurity Dive, 2026-05-14https://www.cybersecuritydive.com/news/west-pharmaceutical-restoring-operations-ransomware-attack/820250/
- cybersecuritynews.cominlineCybersecurityNews, 2026-05-19https://cybersecuritynews.com/compromised-github-action-exfiltrates-workflow-credentials/
- cybersecuritynews.cominlineCybersecurityNews, 2026-05-19https://cybersecuritynews.com/nx-console-vs-code-extension-compromised/
- cybersecuritynews.cominlineCybersecurityNewshttps://cybersecuritynews.com/veeam-backup-replication-tool-vulnerability/
- cyera.cominlineCyera Research, 2026-05-15https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw
- depthfirst.cominlinedepthfirst — 21 zero-days in FFmpeghttps://depthfirst.com/research/21-zero-days-in-ffmpeg
- depthfirst.cominlinedepthfirst "NGINX Rift" research, 2026-05-13https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability
- digital-strategy.ec.europa.euinlineEuropean Commission, 2026-06-17https://digital-strategy.ec.europa.eu/en/news/european-commission-welcomes-g7-cybersecurity-declaration-strengthen-global-digital-resilience
- dlapiper.cominlineDLA Piper — NIS2 update EU moves to harmonise cyber controlshttps://www.dlapiper.com/en/insights/publications/2026/02/nis2-update-eu-moves-to-harmonise-cyber-controls-refine-scope-and-add-new-in-scope-entities
- docs.gitlab.cominlineGitLab — patch release 19.0.1https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/
- docs.litellm.aiinlineLiteLLM vendor advisoryhttps://docs.litellm.ai/blog/cve-2026-42208-litellm-proxy-sql-injection
- dragos.cominlineDragos — AI-assisted ICS attack water utilityhttps://www.dragos.com/blog/ai-assisted-ics-attack-water-utility/
- dragos.cominlineDragos — 8th Annual OT Cybersecurity Year in Review blog announcementhttps://www.dragos.com/blog/dragos-8th-annual-ot-cybersecurity-year-in-review-is-now-available
- dragos.cominlineDragos, 2026-06-03https://www.dragos.com/dragos-industrial-ransomware-analysis-q1-2026
- dragos.cominlineDragos — 2025 OT Cybersecurity Year in Reviewhttps://www.dragos.com/year-in-review/
- drupal.orginlineDrupal PSA, 2026-05-18https://www.drupal.org/psa-2026-05-18
- drupal.orginlineDrupal Security Team — SA-CORE-2026-004https://www.drupal.org/sa-core-2026-004
- drupal.orginlineDrupal SA-CORE-2026-005https://www.drupal.org/sa-core-2026-005
- drupal.orginlineDrupal SA-CORE-2026-006https://www.drupal.org/sa-core-2026-006
- drupal.orginlineDrupal SA feedhttps://www.drupal.org/security
- drupal.orginlineDrupal Steward WAFhttps://www.drupal.org/steward
- dutchnews.nlinlineDutchNews.nl — Hackers break into ed-tech giant againhttps://www.dutchnews.nl/2026/05/hackers-break-into-ed-tech-giant-again-after-massive-data-heist/
- edri.orginlineEDRihttps://edri.org/our-work/inside-italys-low-cost-spyware-economy/
- elastic.coinlineElastic Security Labshttps://www.elastic.co/security-labs/aad-graph-activity-logs-threat-detection
- elastic.coinlineElastic Security Labs, 2026-05-26https://www.elastic.co/security-labs/tycoon-2fa-aitm-detection-engineering
- emsisoft.cominlineEmsisofthttps://www.emsisoft.com/en/blog/47562/the-state-of-ransomware-in-q1-2026/
- enisa.europa.euinlineENISA, 2026-05-06https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root
- enki.co.krinlineENKI WhiteHathttps://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant
- esentire.cominlineeSentire Threat Response Unit, 2026-05-12https://www.esentire.com/blog/tycoon-2fa-operators-adopt-oauth-device-code-phishing
- eurojust.europa.euinlineEurojust — First VPN takedownhttps://www.eurojust.europa.eu/news/eurojust-coordinated-investigation-shuts-down-criminal-vpn-network
- europol.europa.euinlineEuropol, 2026-06-24https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks
- euvd.enisa.europa.euinlineENISA EUVDhttps://euvd.enisa.europa.eu/enisa/EUVD-2026-37966
- euvd.enisa.europa.euinlineENISA EUVD EUVD-2026-30537https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-30537
- euvd.enisa.europa.euinlineENISA EUVD-2026-30931https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-30931
- euvd.enisa.europa.euinlineENISA EUVD EUVD-2026-32027, 2026-05-27https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-32027
- euvd.enisa.europa.euinlineENISA EUVD EUVD-2026-34268https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-34268
- fiod.nlinlineFIOD — Stark Industries arrestshttps://www.fiod.nl/fiod-houdt-twee-verdachten-aan-wegens-overtreding-sanctiewetgeving/
- flare.ioinlineFlare.io — PamDOORa, 2026-05-07https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web
- flatt.techinlineGMO Flatt Security — claude-code-actionhttps://flatt.tech/research/posts/poisoning-claude-code-one-github-issue-to-break-the-supply-chain/
- forescout.cominlineForescout Vedere Labs — BRIDGE:BREAKhttps://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/
- fortiguard.fortinet.cominlineFortinet PSIRT FG-IR-26-099https://fortiguard.fortinet.com/psirt/FG-IR-26-099
- fortiguard.fortinet.cominlineFortinet PSIRT FG-IR-26-128https://fortiguard.fortinet.com/psirt/FG-IR-26-128
- fortiguard.fortinet.cominlineFortinet PSIRT FG-IR-26-136https://fortiguard.fortinet.com/psirt/FG-IR-26-136
- fortinet.cominlineFortinet PSIRThttps://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices
- fortinet.cominlineFortiGuard Labshttps://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026
- fortinet.cominlineFortiGuard Labshttps://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo
- gambit.securityinlineGambit Securityhttps://gambit.security/blog-posts/babil-of-minab-iran-mois-destruction-campaign
- github.bloginlineGitHub Changelog — staged publishing GAhttps://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/
- github.bloginlineGitHub Changeloghttps://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
- github.bloginlineGitHub Changelog — actions/checkout safer defaultshttps://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/
- github.bloginlineGitHub Security Blog — internal-repo accesshttps://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/
- gizmodo.cominlineGizmodohttps://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330
- global.toshibainlineToshiba, 2026-06-02https://www.global.toshiba/jp/top/info-20260602.html
- globalbankingandfinance.cominlineGlobal Banking & Finance Review, 2026-06-16https://www.globalbankingandfinance.com/hacking-group-claims-major-hack-novo-nordisk-attempted-25/
- globalpolicywatch.cominlineCovington — Cybersecurity Act 2, 2026-01-23https://www.globalpolicywatch.com/2026/01/european-commission-proposes-cybersecurity-act-2-new-eu-supply-chain-rules-and-certification-reforms/
- globalsecurity.orginlineGlobal Security, 2026-06-12https://www.globalsecurity.org/security/library/news/2026/06/sec-260612-doj01.htm
- globenewswire.cominlineVerizon official press release (GlobeNewswire)https://www.globenewswire.com/news-release/2026/05/19/3297614/0/en/Vulnerability-Exploitation-Top-Breach-Entry-Point-2026-Industry-Wide-DBIR-Finds.html
- globenewswire.cominlineGlobeNewswire — Rapid7 Q1 2026 releasehttps://www.globenewswire.com/news-release/2026/05/21/3299378/36514/en/Rapid7-Q1-2026-Threat-Landscape-Report-Finds-Vulnerability-Exploitation-Overtakes-Social-Engineering-as-the-Top-Initial-Access-Vector.html
- godaddy.cominlineGoDaddy Securityhttps://www.godaddy.com/resources/news/malware-targeting-wordpress-abuses-steam-community-profiles
- grafana.cominlineGrafana Labs, 2026-05-19https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/
- hackread.cominlineHackread, 2026-05-16https://hackread.com/pwn2own-berlin-2026-hits-capacity-hackers-0-days/
- hadrian.ioinlineHadrian Securityhttps://hadrian.io/blog/cve-2026-45829----chromadb-python-server-hands-you-rce-before-it-asks-who-you-are
- heise.deinlineheise online, 2026-06-04https://www.heise.de/en/news/IT-researchers-demonstrate-adaptive-AI-worm-11318259.html
- heise.deinlineheise Securityhttps://www.heise.de/en/news/Too-many-zero-days-Microsoft-threatens-legal-action-11310736.html
- heise.deinlineheise Security (DE)https://www.heise.de/news/Angriffe-auf-Burst-Statistics-Plugin-fuer-WordPress-11317017.html
- heise.deinlineheise online, 2026-05-07https://www.heise.de/news/Cyberkrieg-Medien-zitieren-Interna-aus-Russlands-Geheimdienstausbildung-11285528.html
- heise.deinlineHeise Securityhttps://www.heise.de/news/Roundcube-Webmail-Instanzen-mit-Schadcode-attackierbar-11307545.html
- heise.deinlineheise, 2026-06-05https://www.heise.de/news/Warten-auf-Sicherheitspatch-Zugangsdaten-von-Acer-Wave-7-Router-einsehbar-11318035.html
- helpnetsecurity.cominlineHelp Net Security — European Commission Ivanti EPMM vulnerabilities, 2026-02-09https://www.helpnetsecurity.com/2026/02/09/european-commission-ivanti-epmm-vulnerabilities/
- helpnetsecurity.cominlineHelp Net Security — Windows CVE-2026-32202 exploitedhttps://www.helpnetsecurity.com/2026/04/29/windows-cve-2026-32202-exploited/
- helpnetsecurity.cominlineHelp Net Security — DigiCert breachhttps://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-06https://www.helpnetsecurity.com/2026/05/06/daemon-tools-compromised-backdoors-supply-chain-attack/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-08https://www.helpnetsecurity.com/2026/05/08/dirty-frag-linux-vulnerability-cve-2026-43284-cve-2026-43500/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-11https://www.helpnetsecurity.com/2026/05/11/google-ai-vulnerability-exploitation/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-12https://www.helpnetsecurity.com/2026/05/12/microsoft-may-2026-patch-tuesday/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-14https://www.helpnetsecurity.com/2026/05/14/fragnesia-cve-2026-46300-linux-lpe-vulnerability/
- helpnetsecurity.cominlineHelp Net Security — Sophos 2026 identity-breach costs reporthttps://www.helpnetsecurity.com/2026/05/14/sophos-2026-identity-breach-costs-report/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-20https://www.helpnetsecurity.com/2026/05/20/github-breached-teampcp/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/
- helpnetsecurity.cominlineHelp Net Security on GitHub root causehttps://www.helpnetsecurity.com/2026/05/21/github-grafana-breach-root-cause-nx-console/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-22https://www.helpnetsecurity.com/2026/05/22/deleted-google-api-keys-risk/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/05/22/kali365-microsoft-365-phishing-fbi-warning/
- helpnetsecurity.cominlineHelp Net Security — FBI Silent Ransom Group alert, 2026-05-27https://www.helpnetsecurity.com/2026/05/27/fbi-silent-ransom-group-law-firms-social-engineering/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/02/ai-agents-edr-evasion-techniques/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/02/android-vulnerability-exploited-cve-2025-48595/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/05/cisco-sd-wan-cve-2026-20245-0-day-exploited/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/15/chinese-hackers-redcap-medical-research-institutions-breach/
- helpnetsecurity.cominlineHelp Net Security, 2026-06-16https://www.helpnetsecurity.com/2026/06/16/dragonforce-microsoft-teams-malware-backdoor-turn/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/17/rogueplanet-zero-day-cve-2026-50656/
- helpnetsecurity.cominlineHelp Net Security, 2026-06-18https://www.helpnetsecurity.com/2026/06/18/eset-gentlemen-edr-killers/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/18/law-enforcement-socgholish-operation-endgame/
- helpnetsecurity.cominlineHelp Net Security, 2026-06-24https://www.helpnetsecurity.com/2026/06/24/lastpass-klue-data-breach-salesforce-environment/
- hkcert.orginlineHKCERT Advisory 20260522https://www.hkcert.org/security-bulletin/trend-micro-apex-one-multiple-vulnerabilities_20260522
- home.treasury.govinlineUS Treasury OFAChttps://home.treasury.gov/news/press-releases/sb0519
- horizon3.aiinlineHorizon3.aihttps://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
- horizon3.aiinlineHorizon3.ai analysishttps://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/
- huntress.cominlineHuntresshttps://www.huntress.com/blog/klue-breach-investigation
- huntress.cominlineHuntress — Potemkinhttps://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack
- huntress.cominlineHuntress Labs' 2026-05-21 IR reporthttps://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps
- huntress.cominlineHuntress Labshttps://www.huntress.com/blog/unpatched-ntlm-leak-windows-search-uri-handler
- ibm.cominlineIBM Security Bulletin node/7274065https://www.ibm.com/support/pages/node/7274065
- ic3.govinlineFBI IC3 PSA260527https://www.ic3.gov/PSA/2026/PSA260527
- imperva.cominlineImpervahttps://www.imperva.com/blog/compromise-openclaw-with-prompt-injections-in-message-objects/
- imperva.cominlineImpervahttps://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/
- imperva.cominlineImperva, 2026-05-21https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-9082-in-drupal-core/
- infosecurity-magazine.cominlineInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/chinese-hackers-exploit-iran-war/
- infosecurity-magazine.cominlineInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/fifteen-jetbrains-marketplace/
- infosecurity-magazine.cominlineInfosecurity Magazine, 2026-05-20https://www.infosecurity-magazine.com/news/github-confirms-breach-vs-code/
- infosecurity-magazine.cominlineInfosecurity Magazine, 2026-05-11https://www.infosecurity-magazine.com/news/shinyhunters-escalates-canvas/
- insidehighered.cominlineInside Higher Ed, 2026-05-11https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/11/instructure-pays-ransom-canvas-hackers
- insurancebusinessmag.cominlineInsurance Business Magazine, 2026-06-16https://www.insurancebusinessmag.com/us/news/cyber/ozempic-maker-novo-nordisk-hit-with-25-million-ransom-demand-after-claimed-data-breach-579161.aspx
- ioctl.failinlineioctl.failhttps://ioctl.fail/preliminary-analysis-of-aur-malware/
- isc.sans.eduinlineSANS ISC diary 33016 — Mini Shai-Hulud framework / Microsoft SDKhttps://isc.sans.edu/diary/33016
- isc.sans.eduinlineSANS Internet Storm Center, 2026-05-26https://isc.sans.edu/diary/33018
- isc.sans.eduinlineSANS Internet Storm Centerhttps://isc.sans.edu/diary/33040
- isc.sans.eduinlineSANS ISC, 2026-06-08https://isc.sans.edu/diary/33060
- isc.sans.eduinlineSANS ISChttps://isc.sans.edu/diary/33094
- isc.sans.eduinlineSANS Internet Storm Center, 2026-05-18https://isc.sans.edu/diary/rss/32994
- isc.sans.eduinlineSANS Internet Storm Centerhttps://isc.sans.edu/diary/rss/33024
- isc.sans.eduinlineSANS Internet Storm Centerhttps://isc.sans.edu/diary/rss/33034
- isc.sans.eduinlineSANS Internet Storm Center (Xavier Mertens)https://isc.sans.edu/diary/rss/33054
- isc.sans.eduinlineSANS ISC, 2026-06-09https://isc.sans.edu/diary/rss/33064
- ivanti.cominlineIvanti PSIRThttps://www.ivanti.com/blog/may-2026-epmm-security-update
- ivanti.cominlineIvanti, 2026-05-12https://www.ivanti.com/blog/may-2026-security-update
- joomlacontenteditor.netinlineWidget Factory / JCE security updatehttps://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites
- jpcert.or.jpinlineJPCERT/CC at260014https://www.jpcert.or.jp/english/at/2026/at260014.html
- justice.govinlineU.S. Department of Justice press releasehttps://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos
- kaspersky.cominlineKaspersky press release, 2026-05-05https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware
- kaspersky.cominlineKaspersky Securelisthttps://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/
- kb.isc.orginlineISC BIND CVE-2026-3593, 2026-05-20https://kb.isc.org/docs/cve-2026-3593
- kb.isc.orginlineISC BIND CVE-2026-5946, 2026-05-20https://kb.isc.org/docs/cve-2026-5946
- kelacyber.cominlineKELA — internal chat-leak analysishttps://www.kelacyber.com/blog/the-gentlemen-ransomware-internal-chat-leak-analysis-2026/
- keycloak.orginlineKeycloak 26.6.3 release noteshttps://www.keycloak.org/2026/06/keycloak-2663-released
- klue.cominlineKlue incident updatehttps://klue.com/blog/an-update-on-recent-klue-security-incident
- kodemsecurity.cominlineKodem Security analysis, 2026-05-19https://www.kodemsecurity.com/resources/vm2-sandbox-escape-vulnerabilities-the-2026-cve-wave-turning-ai-agents-into-host-rce-vectors
- krebsonsecurity.cominlineKrebsOnSecurityhttps://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/
- krebsonsecurity.cominlineKrebs on Securityhttps://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- krebsonsecurity.cominlineKrebs on Security, 2026-05-12https://krebsonsecurity.com/2026/05/patch-tuesday-may-2026-edition/
- krebsonsecurity.cominlineKrebs on Securityhttps://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
- krebsonsecurity.cominlineKrebs on Securityhttps://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/
- krebsonsecurity.cominlineKrebsOnSecurity, 2026-06-10https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
- labs.cloudsecurityalliance.orginlineCloud Security Alliance — Shai-Hulud/Megalodon research notehttps://labs.cloudsecurityalliance.org/research/csa-research-note-shai-hulud-megalodon-supply-chain-cascade/
- labs.infoguard.chinlineInfoGuard, 2026-06-09https://labs.infoguard.ch/posts/ghost-sender/
- labs.watchtowr.cominlinewatchTowr Labshttps://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/
- labs.watchtowr.cominlinewatchTowr Labs — CVE-2026-41940https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
- labs.watchtowr.cominlinewatchTowr Labshttps://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
- labs.withsecure.cominlineWithSecure Labshttps://labs.withsecure.com/publications/greyvibe
- learn.microsoft.cominlineASR rules referencehttps://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference
- legalcheek.cominlineLegal Cheek, 2026-06-03https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/
- lemonde.frinlineLe Monde — Bauman clandestine schoolhttps://www.lemonde.fr/en/m-le-mag/article/2026/05/07/moscow-s-bauman-university-the-clandestine-school-training-russian-hackers_6753208_117.html
- lumen.cominlineLumen Black Lotus Labshttps://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation
- lumen.cominlineLumen Black Lotus Labs — Showboathttps://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms
- maine.govinlineMaine AG breach notification, 2026-05-01https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/4fe778c0-a3a9-4dbe-8e79-2c229ac5c36b.html
- maine.govinlineMaine AG data-breach filinghttps://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/d6729ef2-7bb3-42d3-abdd-99a1dd8f2415.html
- malware.newsinlineWordfence via Malware.newshttps://malware.news/t/critical-unauthenticated-authentication-bypass-vulnerability-patched-in-updraftplus-wordpress-plugin/107751
- malwarebytes.cominlineMalwarebytes Labshttps://www.malwarebytes.com/blog/news/2026/05/signal-users-targeted-in-backup-stealing-phishing-attacks
- malwarebytes.cominlineMalwarebyteshttps://www.malwarebytes.com/blog/news/2026/06/kodak-confirms-breach-as-shinyhunters-leak-threat-reaches-deadline
- malwarebytes.cominlineMalwarebytes, 2026-04-10https://www.malwarebytes.com/blog/scams/2026/04/fake-claude-site-installs-malware-that-gives-attackers-access-to-your-computer
- malwarebytes.cominlineMalwarebytes — Shub Stealer earlier wave, 2026-03https://www.malwarebytes.com/blog/threat-intel/2026/03/fake-cleanmymac-site-installs-shub-stealer-and-backdoors-crypto-wallets
- mariadb.cominlineMariaDB CVE listhttps://mariadb.com/docs/server/security/cve/community-server
- mariadb.orginlineMariaDB Foundation corrective releaseshttps://mariadb.org/mariadb-community-server-corrective-releases/
- meduza.ioinlineMeduza (English) — Department No. 4 investigationhttps://meduza.io/amp/en/feature/2026/05/07/secret-gru-linked-department-at-top-russian-university-trains-hackers-and-saboteurs-investigation-finds
- mi5.gov.ukinlineMI5 — Five Eyes joint bulletinhttps://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets
- microsoft.cominlineMicrosoft Security Blog, 2026-05-06https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/
- microsoft.cominlineMicrosoft Security Blog — Prompts become shellshttps://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/
- microsoft.cominlineMicrosoft Security Bloghttps://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/
- microsoft.cominlineMicrosoft Security Blog, 2026-05-12https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-finds-16-new-vulnerabilities/
- microsoft.cominlineMicrosoft Threat Intelligence — Storm-2949, 2026-05-18https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/
- microsoft.cominlineMicrosoft Threat Intelligence — Fox Tempesthttps://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
- microsoft.cominlineMicrosoft Security Blog — search-poisoning cryptojackinghttps://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/
- microsoft.cominlineMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/
- microsoft.cominlineMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environments/
- microsoft.cominlineMicrosoft — AI brands as baithttps://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/
- microsoft.cominlineMicrosoft Securityhttps://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/
- microsoft.cominlineMicrosoft Security — Mastrahttps://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/
- microsoft.cominlineMicrosoft Security — AutoJackhttps://www.microsoft.com/en-us/security/blog/2026/06/18/autojack-single-page-rce-host-running-ai-agent/
- microsoft.cominlineMicrosoft, 2026-06-24https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/
- misp-project.orginlineMISP 2.5.42 release noteshttps://www.misp-project.org/2026/06/22/misp.2.5.42.release.html/
- moselwal.cominlineMoselwal technical analysis, 2026-05-18https://moselwal.com/blog/dirtydecrypt-linux-kernel-rxgk-cve-2026-31635
- moxfive.cominlineMOXFIVE, 2026-06-10https://www.moxfive.com/blog/who-is-fulcrumsec-inside-the-cloud-extortion-group-behind-21-victims-and-counting
- msrc.microsoft.cominlineMicrosoft MSRC CVE-2026-26142https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-26142
- msrc.microsoft.cominlineMicrosoft MSRC CVE-2026-41089https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089
- msrc.microsoft.cominlineMicrosoft MSRC — CVE-2026-41091https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091
- msrc.microsoft.cominlineMicrosoft MSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42822
- msrc.microsoft.cominlineMicrosoft Security Bloghttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897
- msrc.microsoft.cominlineMSRC CVE-2026-45584, 2026-05-19https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45584
- msrc.microsoft.cominlineMSRC — CVE-2026-45585https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585
- msrc.microsoft.cominlineMicrosoft MSRC CVE-2026-45657https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45657
- msrc.microsoft.cominlineMicrosoft MSRC, 2026-06-09https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47291
- msrc.microsoft.cominlineMicrosoft MSRC CVE-2026-47643https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47643
- msrc.microsoft.cominlineMicrosoft MSRC CVE-2026-48579https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-48579
- msrc.microsoft.cominlineMicrosoft MSRC — CVE-2026-32202https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202
- msrc.microsoft.cominlineMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
- msrc.microsoft.cominlineMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656
- my.f5.cominlineF5 K000160932, 2026-05-14https://my.f5.com/manage/s/article/K000160932
- my.f5.cominlineF5 PSIRT advisory K000161019https://my.f5.com/manage/s/article/K000161019
- ncsc.admin.chinlineNCSC-CH pre-event advisoryhttps://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/massnahmen-grossanlaesse-konferenzen-g7.html
- ncsc.admin.chinlineNCSC Switzerlandhttps://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_22.html
- news.risky.bizinlineRisky Business, 2026-06-18https://news.risky.biz/risky-bulletin-china-arrests-members-of-silver-fox-cybercrime-group/
- news.risky.bizinlineRisky Business News bulletinhttps://news.risky.biz/risky-bulletin-dutch-police-take-down-giant-botnet-of-17-million-devices/
- newsroom.adt.cominlineADT Newsroomhttps://newsroom.adt.com/corporate-news/adt-detects-cybersecurity-incident
- nginx.orginlineNGINX security advisorieshttps://nginx.org/en/security_advisories.html
- nlnetlabs.nlinlineNLnet Labs — CVE-2026-33278 advisory, 2026-05-20https://nlnetlabs.nl/downloads/unbound/CVE-2026-33278.txt
- nlnetlabs.nlinlineNLnet Labs — Unbound 1.25.1 release, 2026-05-20https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/
- nltimes.nlinlineNL Times — Canvas hack: student data from 44 Dutch universities and schools takenhttps://nltimes.nl/2026/05/05/canvas-hack-student-data-44-dutch-universities-schools-taken-massive-breach
- nltimes.nlinlineNL Timeshttps://nltimes.nl/2026/05/28/ncsc-dutch-police-disrupt-global-botnet-controlled-via-netherlands-based-servers
- nottingham.ac.ukinlineUniversity of Nottinghamhttps://www.nottingham.ac.uk/currentstudents/news/student-and-alumni-data-has-been-compromised-in-a-data-security-incident
- novee.securityinlineNovee Security — Cordycepshttps://novee.security/blog/cordyceps/
- nvd.nist.govinlineNVD — CVE-2026-32202https://nvd.nist.gov/vuln/detail/CVE-2026-32202
- nvd.nist.govinlineNVD — CVE-2026-5787https://nvd.nist.gov/vuln/detail/CVE-2026-5787
- nvd.nist.govinlineNVD — CVE-2026-6973https://nvd.nist.gov/vuln/detail/CVE-2026-6973
- nx.devinlineNx postmortemhttps://nx.dev/blog/nx-console-v18-95-0-postmortem
- obsidiansecurity.cominlineObsidian — LiteLLMhttps://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce
- onapsis.cominlineOnapsishttps://onapsis.com/blog/sap-security-patch-day-june-2026
- onapsis.cominlineOnapsis, 2026-05-12https://onapsis.com/blog/sap-security-patch-day-may-2026/
- opensourcemalware.cominlineOpenSourceMalwarehttps://opensourcemalware.com/blog/miasma-reaches-azure
- openwall.cominlineoss-security, 2026-05-12https://www.openwall.com/lists/oss-security/2026/05/12/4
- openwall.cominlineoss-security mailing list / V12 Securityhttps://www.openwall.com/lists/oss-security/2026/05/19/6
- openwall.cominlineoss-securityhttps://www.openwall.com/lists/oss-security/2026/05/27/6
- openwall.cominlineoss-security mailing listhttps://www.openwall.com/lists/oss-security/2026/06/03/3
- optinmonster.cominlineOptinMonsterhttps://optinmonster.com/security-incident-tampered-script-served-via-optinmonster-and-trustpulse/
- oracle.cominlineOracle security alerthttps://www.oracle.com/security-alerts/alert-cve-2026-35273.html
- oracle.cominlineOracle CPU July 2024https://www.oracle.com/security-alerts/cpujul2024.html
- oracle.cominlineOracle CSPU advisoryhttps://www.oracle.com/security-alerts/cspujun2026.html
- ostif.orginlineOSTIF — BadHost disclosurehttps://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/
- ox.securityinlineOX Securityhttps://www.ox.security/blog/megalodon-cicd-malware-github/
- ox.securityinlineOX Security — TeamPCP copycatshttps://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/
- panelica.cominlinePanelica — cPanel CVE-2026-29201/29202/29203 advisoryhttps://panelica.com/blog/cpanel-cve-2026-29201-29202-29203-may-2026-tsr-advisory
- patchstack.cominlinePatchstackhttps://patchstack.com/articles/supply-chain-attack-on-optinmonster-trustpulse-and-pushengage-tampered-cdn-scripts-auto-creating-rogue-admins/
- patchstack.cominlinePatchstack — Kirki advisoryhttps://patchstack.com/database/wordpress/plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-0-6-0-6-unauthenticated-privilege-escalation-via-handle-forgot-password-vulnerability
- penligent.aiinlinePenligent/Barghest researchhttps://www.penligent.ai/hackinglabs/cve-2026-0073-android-adbd-zero-click-shell-through-wireless-adb/
- pentest-tools.cominlinePentest-Tools.com researchhttps://pentest-tools.com/research/phpbb-authentication-bypass
- permiso.ioinlinePermiso Security — ChatGPhishhttps://permiso.io/blog/chatgpt-markdown-rendering-vulnerability
- pgadmin.orginlinepgAdmin release noteshttps://www.pgadmin.org/docs/pgadmin4/9.16/release_notes_9_16.html
- php.netfooterPHP 8 ChangeLoghttps://www.php.net/ChangeLog-8.php
- php.watchfooterphp.watch — PHP 8.5.6 releasehttps://php.watch/versions/8.5/releases/8.5.6
- phpbb.cominlinephpBB community announcementhttps://www.phpbb.com/community/viewtopic.php?p=16116763
- piunikaweb.cominlinePiunikaWeb — JDownloader compromisedhttps://piunikaweb.com/2026/05/08/jdownloader-website-hacked-malware/
- politie.nlinlinePolitie, 2026-06-18https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html
- politie.nlinlinePolitie.nl — botnet takedownhttps://www.politie.nl/nieuws/2026/mei/28/06-politie-en-ncsc-halen-groot-botnetwerk-offline.html
- posthogstatus.cominlinePostHog incident statushttps://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1
- postquantum.cominlinePostQuantum.com — EU PQC NIS2https://postquantum.com/security-pqc/eu-pqc-nis2/
- prnewswire.cominlineCarnival Corporation — Notice of Data Breachhttps://www.prnewswire.com/news-releases/carnival-corporation-notice-of-data-breach-302783524.html
- proofpoint.cominlineProofpointhttps://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal
- proofpoint.cominlineProofpointhttps://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation
- proofpoint.cominlineProofpoint/IBM X-Force, 2026-06-24https://www.proofpoint.com/us/blog/threat-insight/stealc-you-later-proofpoint-and-ibm-x-force-support-operation-endgame
- ps.tcinlineParadigm Shift Technologyhttps://ps.tc/pages/blog-usbliter8.html
- ptc.cominlinePTC PSIRT advisoryhttps://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability
- pushsecurity.cominlinePush Security — LLMSharehttps://pushsecurity.com/blog/llmshare-malvertising-campaign
- qurium.orginlineQurium Media Foundationhttps://www.qurium.org/forensics/finding-popa/
- rapid7.cominlineRapid7, 2026-06-09https://www.rapid7.com/blog/post/em-patch-tuesday-june-2026
- rapid7.cominlineRapid7https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/
- rapid7.cominlineRapid7https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751/
- rapid7.cominlineRapid7 ETR — observed exploitationhttps://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/
- rapid7.cominlineRapid7 Q1 2026 Threat Landscape Reporthttps://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/
- rapid7.cominlineRapid7 Labs — Gogs unpatched RCEhttps://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
- rapid7.cominlineRapid7, 2026-05-14https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/
- redcanary.cominlineRed Canary, 2026-06-08https://redcanary.com/blog/threat-detection/entra-id-ai-workflows-assistive-agents/
- redcanary.cominlineRed Canary — Entra Agent IDhttps://redcanary.com/blog/threat-detection/entra-id-ai-workflows/
- redis.ioinlineRedis, 2026-05-05https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/
- reliaquest.cominlineReliaQuesthttps://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft
- reliaquest.cominlineReliaQuest — OP-512 threat spotlighthttps://reliaquest.com/blog/threat-spotlight-reliaquests-agentic-ai-uncovers-new-china-linked-cluster-op-512
- research.checkpoint.cominlineCheck Point Research DFIR Report, 2026-04-20https://research.checkpoint.com/2026/dfir-report-the-gentlemen/
- research.checkpoint.cominlineCheck Point Researchhttps://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer/
- research.checkpoint.cominlineCheck Point Researchhttps://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijacker/
- research.checkpoint.cominlineCheck Point Research, 2026-06-03https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/
- research.checkpoint.cominlineCheck Point Researchhttps://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/
- research.checkpoint.cominlineCheck Point Research — Thus Spoke The Gentlemenhttps://research.checkpoint.com/2026/thus-spoke-the-gentlemen/
- research.jfrog.cominlineJFrog Security Researchhttps://research.jfrog.com/post/easy-day-js/
- research.jfrog.cominlineJFrog Security Researchhttps://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/
- research.jfrog.cominlineJFrog Security Research — IronWormhttps://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/
- roundcube.netinlineRoundcube Projecthttps://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
- safedep.ioinlineSafeDep — Megalodonhttps://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/
- samba.orginlineSamba Project — CVE-2026-4408https://www.samba.org/samba/security/CVE-2026-4408.html
- samba.orginlineSamba Project — CVE-2026-4480https://www.samba.org/samba/security/CVE-2026-4480.html
- sansec.ioinlineSansec researchhttps://sansec.io/research/funnelkit-woocommerce-vulnerability-exploited
- sansec.ioinlineSansechttps://sansec.io/research/mirasvit-cache-warmer-object-injection
- sansec.ioinlineSansec — OptinMonsterhttps://sansec.io/research/optinmonster-supply-chain-attack
- sansec.ioinlineSansec — Stripe API skimmerhttps://sansec.io/research/stripe-api-skimmer-infrastructure
- scworld.cominlineSC Mediahttps://www.scworld.com/brief/ubiquiti-unifi-os-server-vulnerabilities-allow-unauthenticated-remote-code-execution
- sec.cloudapps.cisco.cominlineCisco PSIRT advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy
- sec.cloudapps.cisco.cominlineCisco PSIRT advisory cisco-sa-cucm-ssrf-cXPnHcWhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
- sec.cloudapps.cisco.cominlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv
- sec.cloudapps.cisco.cominlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ
- sec.cloudapps.cisco.cominlineCisco PSIRT cisco-sa-sdwan-privesc-4uxFrdzxhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx
- sec.cloudapps.cisco.cominlineCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
- sec.govinlineSEC EDGAR 8-K/Ahttps://www.sec.gov/Archives/edgar/data/0000105770/000010577026000077/wst-20260507.htm
- sec.govinlineSEC EDGAR — 8x8 Form 8-K, 2026-06-23https://www.sec.gov/Archives/edgar/data/0001023731/000102373126000084/eght-20260617.htm
- sec.govinlineSEC 8-K — iRhythmhttps://www.sec.gov/Archives/edgar/data/0001388658/000138865826000055/irtc-20260610.htm
- sec.govinlineSEC EDGAR — WST 8-K, 2026-05-11https://www.sec.gov/Archives/edgar/data/105770/000010577026000068/wst-20260507.htm
- seclists.orginlineoss-security / Califhttps://seclists.org/oss-sec/2026/q2/790
- secretservice.govinlineUS Secret Servicehttps://www.secretservice.gov/newsroom/releases/2026/06/two-charged-connection-cryptocurrency-money-laundering-service-allegedly
- securelist.cominlineKaspersky Securelist — Amazon SES BEC Campaign (2026-05-04)https://securelist.com/amazon-ses-bec-campaign-2026/
- securelist.cominlineKaspersky Securelist — CVE-2025-68670, 2026-05-08https://securelist.com/cve-2025-68670/119742/
- securelist.cominlineKaspersky Securelist — Exploits and Vulnerabilities Q1 2026https://securelist.com/exploits-vulnerabilities-q1-2026/
- securelist.cominlineKaspersky Securelist, 2026-05-14https://securelist.com/kimsuky-appleseed-pebbledash-campaigns/119785/
- securelist.cominlineSecurelist (Kaspersky), 2026-05-12https://securelist.com/state-of-ransomware-in-2026/119761/
- securelist.cominlineKaspersky Securelist, 2026-05-06https://securelist.com/tr/daemon-tools-backdoor/119654/
- securelist.cominlineKaspersky Securelist — Exploits and Vulnerabilities Q1 2026https://securelist.com/vulnerabilities-and-exploits-in-q1-2026/119733/
- securelist.cominlineKaspersky, 2026-06-22https://securelist.com/whatsapp-vbs-rmm-campaign/120290/
- security-hub.ncsc.admin.chinlineNCSC Switzerland Security Hub, 2026-05-29https://security-hub.ncsc.admin.ch/#/posts/12548
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub #12558, 2026-05-12https://security-hub.ncsc.admin.ch/#/posts/12558
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub #12565, 2026-05-12https://security-hub.ncsc.admin.ch/#/posts/12565
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub #12569, 2026-05-13https://security-hub.ncsc.admin.ch/#/posts/12569
- security-hub.ncsc.admin.chinlineNCSC.ch Security Hub #12574https://security-hub.ncsc.admin.ch/#/posts/12574
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub post #12575https://security-hub.ncsc.admin.ch/#/posts/12575
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub #12577, 2026-05-15https://security-hub.ncsc.admin.ch/#/posts/12577
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub advisory 12579https://security-hub.ncsc.admin.ch/#/posts/12579
- security-hub.ncsc.admin.chinlineNCSC.ch Security Hub post 12584https://security-hub.ncsc.admin.ch/#/posts/12584
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub, 2026-05-21https://security-hub.ncsc.admin.ch/#/posts/12588
- security-hub.ncsc.admin.chinlineNCSC.ch Security Hub post 12596https://security-hub.ncsc.admin.ch/#/posts/12596
- security-hub.ncsc.admin.chinlineNCSC.ch Security Hub post 12601https://security-hub.ncsc.admin.ch/#/posts/12601
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12605
- security-hub.ncsc.admin.chinlineNCSC-CH advisory 12610https://security-hub.ncsc.admin.ch/#/posts/12610
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12615
- security-hub.ncsc.admin.chinlineNCSC-CH, 2026-06-09https://security-hub.ncsc.admin.ch/#/posts/12620
- security-hub.ncsc.admin.chinlineNCSC-CH GovCERThttps://security-hub.ncsc.admin.ch/#/posts/12621
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12622
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub post 12627https://security-hub.ncsc.admin.ch/#/posts/12627
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12639
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12720
- security-hub.ncsc.admin.chinlineSecurity Hub post 12547https://security-hub.ncsc.admin.ch/api/posts/12547/details
- security-hub.ncsc.admin.chinlineNCSC-CH 12548, 2026-05-08https://security-hub.ncsc.admin.ch/api/posts/12548/details
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub post 12550https://security-hub.ncsc.admin.ch/api/posts/12550/details
- security-hub.ncsc.admin.chinlineNCSC.ch Security Hub #12577https://security-hub.ncsc.admin.ch/api/posts/12577/details
- security.cominlineBroadcom Securityhttps://www.security.com/blog-post/fast16-nuclear-sabotage
- security.cominlineSymantec / Broadcom, 2026-06-16https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor
- security.cominlineBroadcom/Symantec, 2026-06-03https://www.security.com/threat-intelligence/stock-exchange-espionage
- security.paloaltonetworks.cominlinePalo Alto Networks PSIRThttps://security.paloaltonetworks.com/CVE-2026-0257
- security.paloaltonetworks.cominlinePalo Alto Networks PSIRThttps://security.paloaltonetworks.com/CVE-2026-0300
- securityaffairs.cominlineSecurityAffairs — Zara breachhttps://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html
- securityaffairs.cominlineSecurity Affairs, 2026-05-14https://securityaffairs.com/192132/hacking/nginx-rift-an-18-year-old-flaw-in-the-worlds-most-deployed-web-server-just-came-to-light.html
- securityaffairs.cominlineSecurity Affairs, 2026-05-18https://securityaffairs.com/192336/data-breach/shinyhunters-hack-7-eleven-franchisee-data-and-salesforce-records-exposed.html
- securityaffairs.cominlineSecurity Affairshttps://securityaffairs.com/193027/security/u-s-cisa-adds-oracle-weblogic-flaw-to-its-known-exploited-vulnerabilities-catalog.html
- securityaffairs.cominlineSecurity Affairs — DNS fast-fluxhttps://securityaffairs.com/193215/cyber-crime/silent-ransom-group-srg-switching-to-dns-fast-flux-infrastructure.html
- securityaffairs.cominlineSecurityAffairshttps://securityaffairs.com/193530/hacking/cve-2026-10520-exploited-ivanti-sentry-gateways-compromised-shortly-after-patch-release.html
- securityaffairs.cominlineSecurity Affairshttps://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html
- securityaffairs.cominlineSecurity Affairs, 2026-06-08https://www.securityaffairs.com/193307/ai/meta-ai-recovery-tool-flaw-exposed-20000-instagram-accounts.html
- securitylabs.datadoghq.cominlineDatadog Security Labshttps://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/
- securityonline.infoinlineSecurityOnlinehttps://securityonline.info/mariadb-security-flaw-cvss-10/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/7-eleven-data-breach-confirmed-after-shinyhunters-ransom-demand/
- securityweek.cominlineSecurityWeek — Braintrust API key rotationhttps://www.securityweek.com/ai-firm-braintrust-prompts-api-key-rotation-after-data-breach/
- securityweek.cominlineSecurityWeek, 2026-06-24https://www.securityweek.com/beyondtrust-lastpass-impacted-by-klue-salesforce-incident/
- securityweek.cominlineSecurityWeek, 2026-05-12https://www.securityweek.com/bwh-hotels-says-hackers-had-access-to-reservation-data-for-6-months/
- securityweek.cominlineSecurityWeek, 2026-05-11https://www.securityweek.com/checkmarx-jenkins-ast-plugin-compromised-in-supply-chain-attack/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/chinese-hackers-target-medical-military-and-ai-research-in-north-america/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/chrome-149-patches-429-vulnerabilities/
- securityweek.cominlineSecurityWeek, 2026-05-15https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-the-sixth-exploited-in-2026/
- securityweek.cominlineSecurityWeek, 2026-04-16https://www.securityweek.com/claude-code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via-comments/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/
- securityweek.cominlineSecurityWeek — DigiCert revokes certificateshttps://www.securityweek.com/digicert-revokes-certificates-after-support-portal-hack/
- securityweek.cominlineSecurityWeek, 2026-05-19https://www.securityweek.com/drupal-to-patch-highly-critical-vulnerability-at-risk-of-quick-exploitation/
- securityweek.cominlineSecurityWeek, 2026-05-04https://www.securityweek.com/edtech-firm-instructure-discloses-data-breach/
- securityweek.cominlineSecurityWeek (exclusive)https://www.securityweek.com/exclusive-how-one-line-of-code-put-billions-of-microsoft-android-app-downloads-at-risk/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/exploitable-ci-cd-vulnerabilities-expose-millions-of-repositories-to-hijacking/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/f5-patches-critical-high-severity-nginx-vulnerabilities/
- securityweek.cominlineSecurityWeek, 2026-05-14https://www.securityweek.com/f5-patches-over-50-vulnerabilities/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/
- securityweek.cominlineSecurityWeek, 2026-05-13https://www.securityweek.com/fortinet-ivanti-patch-critical-vulnerabilities/
- securityweek.cominlineSecurityWeek, 2026-06-22https://www.securityweek.com/fortinet-responds-to-fortibleed-campaign/
- securityweek.cominlineSecurityWeek, 2026-05-11https://www.securityweek.com/google-detects-first-ai-generated-zero-day-exploit/
- securityweek.cominlineSecurityWeek — Grafana confirms breachhttps://www.securityweek.com/grafana-confirms-breach-after-hackers-claim-they-stole-data/
- securityweek.cominlineSecurityWeek — GreatXMLhttps://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/
- securityweek.cominlineSecurityWeek, 2026-06-03https://www.securityweek.com/hackers-target-global-stock-exchange-in-espionage-operation/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/http-2-bomb-exploit-knocks-web-servers-offline-in-seconds/
- securityweek.cominlineSecurityWeek, 2026-05-08https://www.securityweek.com/ivanti-patches-epmm-zero-day-exploited-in-targeted-attacks/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/kirki-burst-statistics-wordpress-plugin-flaws-in-attackers-crosshairs/
- securityweek.cominlineSecurityWeek — Kodakhttps://www.securityweek.com/kodak-admits-data-breach-after-shinyhunters-hack-claims/
- securityweek.cominlineSecurityWeek, 2026-06-22https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/new-mistic-rat-opens-door-to-several-ransomware-families/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/new-windows-zero-day-exploit-rogueplanet-released/
- securityweek.cominlineSecurityWeek, 2026-06-11https://www.securityweek.com/oracle-addresses-peoplesoft-vulnerability-amid-reports-of-zero-day-attacks/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/oracles-second-monthly-security-updates-deliver-245-patches/
- securityweek.cominlineSecurityWeek — PCPJack wormhttps://www.securityweek.com/pcpjack-worm-removes-teampcp-infections-steals-credentials/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/russia-linked-greyvibe-attackers-use-ai-to-supercharge-cyberattacks/
- securityweek.cominlineSecurityWeek, 2026-06-23https://www.securityweek.com/russian-initial-access-broker-behind-fortibleed-campaign/
- securityweek.cominlineSecurityWeek, 2026-05-12https://www.securityweek.com/sap-patches-critical-s-4hana-commerce-vulnerabilities/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/
- securityweek.cominlineSecurityWeek — Council of Europehttps://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/splunk-enterprise-vulnerability-exploited-in-attacks-days-after-disclosure/
- securityweek.cominlineSecurityWeek, 2026-05-23https://www.securityweek.com/underminr-vulnerability-lets-attackers-hide-malicious-connections-behind-trusted-domains/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/
- sentinelone.cominlineSentinelOne Labshttps://www.sentinelone.com/blog/living-off-the-pipeline-defending-against-ci-cd-subversion/
- sentinelone.cominlineSentinelLabs — Cloud worm evicts TeamPCPhttps://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/
- seqrite.cominlineSeqrite Labs — Dragon Weavehttps://www.seqrite.com/blog/operation-dragon-weave-uncovering-a-china-linked-campaign-targeting-czech-republic-and-taiwan-using-azure-cloud-c2/
- simple-help.cominlineSimpleHelphttps://simple-help.com/security/simplehelp-security-update-2026-05
- skadden.cominlineSkadden — Potential NIS2 cybersecurity reformhttps://www.skadden.com/insights/publications/2026/03/european-commission-announces-potential-nis2-cybersecurity-reform
- slcyber.ioinlineSearchlight Cyber write-uphttps://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/
- snyk.ioinlineSnyk, 2026-06-16https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/
- socket.devinlineSocket — Laravel-Lang, 2026-05-23https://socket.dev/blog/laravel-lang-compromise
- socket.devinlineSocket — postinstall strand, 2026-05-22https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos
- socket.devinlineSockethttps://socket.dev/blog/mastra-npm-packages-compromised
- socket.devinlineSockethttps://socket.dev/blog/mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages
- socket.devinlineSonatype security advisory — node-ipc backdoorhttps://socket.dev/blog/node-ipc-package-compromised
- socket.devinlineSocket, 2026-06-07https://socket.dev/blog/shai-hulud-descends-to-hades-miasma-pypi-wave
- socket.devinlineSocket — TrapDoorhttps://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates
- socradar.ioinlineSOCRadar, 2026-06-16https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/
- solarwinds.cominlineSolarWinds Trust Center advisory CVE-2026-28318https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318
- sonatype.cominlineSonatype — Atomic Archhttps://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency
- sonatype.cominlineSonatypehttps://www.sonatype.com/blog/inside-a-176-package-npm-campaign-built-to-beat-your-internal-dependencies
- sophos.cominlineSophos X-Ops 2026 Active Adversary Reporthttps://www.sophos.com/en-us/blog/2026-sophos-active-adversary-report
- sophos.cominlineSophos X-Opshttps://www.sophos.com/en-us/blog/ai-in-the-underground-curiosity-claims-and-concerns
- sophos.cominlineSophos X-Ops, 2026-05-07https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor
- sophos.cominlineSophos X-Opshttps://www.sophos.com/en-us/blog/pointing-a-cursor-at-evading-detection
- sophos.cominlineSophos bloghttps://www.sophos.com/en-us/blog/sophos-state-of-identity-security-2026
- sophos.cominlineSophos press releasehttps://www.sophos.com/en-us/press/press-releases/2026/05/71-percent-organizations-suffered-identity-breach-state-of-identity-security-2026
- source.android.cominlineAndroid Security Bulletin May 2026https://source.android.com/docs/security/bulletin/2026/2026-05-01
- source.android.cominlineAndroid Security Bulletinhttps://source.android.com/docs/security/bulletin/2026/2026-06-01
- spiegel.deinlineDer Spiegel — Hybrider Krieghttps://www.spiegel.de/ausland/hybrider-krieg-moskau-bildet-in-einem-geheimen-uni-programm-spione-und-hacker-aus-a-2de79023-aa56-4ed6-b5de-d7c222402e63
- sploit.techinlinesploit.tech write-uphttps://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html
- spring.ioinlineSpring.io security advisory — CVE-2026-40982, 2026-05-06https://spring.io/security/cve-2026-40982
- spycloud.cominlineSpyCloud, 2026-06-19https://spycloud.com/blog/what-spycloud-found-inside-the-fortibleed-threat-actor-infrastructure/
- stepsecurity.ioinlineStepSecurity, 2026-05-18https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials
- stepsecurity.ioinlineStepSecurity, 2026-05-22https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack
- stepsecurity.ioinlineStepSecurityhttps://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents
- stepsecurity.ioinlineStepSecurity, 2026-05-21https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem
- stepsecurity.ioinlineStepSecurity, 2026-05-14https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack
- strongswan.orginlinestrongSwan, 2026-06-08https://www.strongswan.org/blog/2026/06/08/strongswan-vulnerability-(cve-2026-47895
- success.trendmicro.cominlineTrend Micro KA-0023430https://success.trendmicro.com/en-US/solution/KA-0023430
- support.adamnet.worksinlineADAMnetworks, 2026-05-21https://support.adamnet.works/t/underminr-information-share-official-release/1584
- support.sap.cominlineSAP, 2026-06-09https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2026.html
- support.sap.cominlineSAP Security Patch Day May 2026https://support.sap.com/en/my-support/knowledge-base/security-notes-news/may-2026.html
- swisscybersecurity.netinlineSwissCybersecurity.nethttps://www.swisscybersecurity.net/news/2026-06-19/neue-cyberaufsicht-kaempft-mit-anlaufschwierigkeiten
- swisspost-cybersecurity.chinlineSwiss Post Cybersecurity, 2026-06-23https://www.swisspost-cybersecurity.ch/news/swiss-threat-landscape-report
- sygnia.coinlineSygnia — Velvet Ant prior reportinghttps://www.sygnia.co/blog/china-nexus-threat-group-velvet-ant/
- sygnia.coinlineSygnia — Operation Highlandhttps://www.sygnia.co/blog/operation-highland-velvet-ant/
- sysdig.cominlineSysdig TRT — LLM-agent post-exploitationhttps://www.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots
- tanstack.cominlineTanStack post-mortem, 2026-05-12https://tanstack.com/blog/npm-supply-chain-compromise-postmortem
- techcommunity.microsoft.cominlineMicrosoft Exchange Team Blog, 2026-05-17https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498
- techcrunch.cominlineTechCrunch, 2026-05-05https://techcrunch.com/2026/05/05/hackers-steal-students-data-during-breach-at-education-tech-giant-instructure/
- techcrunch.cominlineTechCrunch — Braintrust breachhttps://techcrunch.com/2026/05/06/ai-evaluation-startup-braintrust-confirms-breach-tells-every-customer-to-rotate-sensitive-keys/
- techcrunch.cominlineTechCrunch, 2026-05-14https://techcrunch.com/2026/05/14/openai-says-hackers-stole-some-data-after-latest-code-security-issue/
- techcrunch.cominlineTechCrunchhttps://techcrunch.com/2026/05/27/crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks/
- techcrunch.cominlineTechCrunchhttps://techcrunch.com/2026/05/28/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks/
- techcrunch.cominlineTechCrunchhttps://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/
- techcrunch.cominlineTechCrunchhttps://techcrunch.com/2026/06/02/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/
- techcrunch.cominlineTechCrunchhttps://techcrunch.com/2026/06/10/cybercriminals-claim-breach-of-oracle-peoplesoft-servers-at-100-plus-organizations/
- techcrunch.cominlineTechCrunchhttps://techcrunch.com/2026/06/10/servicenow-tells-customers-a-bug-left-some-of-their-data-exposed-to-the-internet/
- technadu.cominlineTechNaduhttps://www.technadu.com/nintendo-confirms-tinypulse-data-stolen-in-shadowbyt3-extortion-attack/629628/
- techzine.euinlineTechzine, 2026-02-16https://www.techzine.eu/news/security/138806/data-breach-at-odido-responsibility-and-compensation-under-discussion/
- techzine.euinlineTechzine EU — Dutch university disconnectshttps://www.techzine.eu/news/security/141149/dutch-university-disconnects-canvas-systems-after-instructure-hack/
- tenable.cominlineTenable, 2026-06-09https://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198-cves-cve-2026-49160-cve-2026-50507
- tenable.cominlineTenable, 2026-05-12https://www.tenable.com/blog/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103
- tenable.cominlineTenable TRA-2026-26https://www.tenable.com/security/research/tra-2026-26
- tenable.cominlineTenable Research TRA-2026-44, 2026-05-26https://www.tenable.com/security/research/tra-2026-44
- tenetsecurity.aiinlineTenet Securityhttps://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/
- thedfirreport.cominlineThe DFIR Report's 2026-05-11 alerthttps://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/
- theguardian.cominlineThe Guardian — Russia top-secret spy schoolhttps://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/chatgphish-vulnerability-turns-chatgpt.html
- thehackernews.cominlineThe Hacker News, 2026-05-19https://thehackernews.com/2026/05/compromised-nx-console-18950-targeted.html
- thehackernews.cominlineThe Hacker News — cPanel/WHM patch 3 new vulnerabilitieshttps://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html
- thehackernews.cominlineThe Hacker News, 2026-05-28https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html
- thehackernews.cominlineThe Hacker News, 2026-05-19https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html
- thehackernews.cominlineThe Hacker News, 2026-05-19https://thehackernews.com/2026/05/drupal-to-release-urgent-core-security.html
- thehackernews.cominlineThe Hacker News, 2026-05-18https://thehackernews.com/2026/05/four-malicious-npm-packages-deliver.html
- thehackernews.cominlineThe Hacker News, 2026-05-15https://thehackernews.com/2026/05/four-openclaw-flaws-enable-data-theft.html
- thehackernews.cominlineThe Hacker News, 2026-05-16https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html
- thehackernews.cominlineThe Hacker News, 2026-05-19https://thehackernews.com/2026/05/github-actions-supply-chain-attack.html
- thehackernews.cominlineThe Hacker News — GitHub investigating TeamPCP claimhttps://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/glassworm-malware-takedown-disrupts.html
- thehackernews.cominlineThe Hacker News — CoinbaseCartel / Grafana breachhttps://thehackernews.com/2026/05/grafana-github-token-breach-led-to.html
- thehackernews.cominlineThe Hacker News, 2026-05-11https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html
- thehackernews.cominlineThe Hacker News — Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitationhttps://thehackernews.com/2026/05/ivanti-epmm-cve-2026-6973-rce-under.html
- thehackernews.cominlineThe Hacker News, 2026-05-18https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html
- thehackernews.cominlineThe Hacker News, 2026-05-28https://thehackernews.com/2026/05/jinx-0164-targets-cryptocurrency-firms.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/kimsuky-deploys-httpspy-expands-arsenal.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/kimwolf-ddos-botnet-operator-arrested.html
- thehackernews.cominlineThe Hacker News, 2026-05-25https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html
- thehackernews.cominlineThe Hacker News, 2026-05-23https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html
- thehackernews.cominlineThe Hacker News, 2026-05-22https://thehackernews.com/2026/05/making-vulnerable-drivers-exploitable.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/megalodon-github-attack-targets-5561.html
- thehackernews.cominlineThe Hacker News — two actively-exploited Defender flawshttps://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html
- thehackernews.cominlineThe Hacker News, 2026-05-19https://thehackernews.com/2026/05/mini-shai-hulud-pushes-malicious-antv.html
- thehackernews.cominlineThe Hacker News, 2026-05-18https://thehackernews.com/2026/05/miniplasma-windows-0-day-enables-system.html
- thehackernews.cominlineThe Hacker News, 2026-05-12https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html
- thehackernews.cominlineThe Hacker News, 2026-05-08https://thehackernews.com/2026/05/new-linux-pamdoora-backdoor-uses-pam.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html
- thehackernews.cominlineVulnCheck honeypot telemetry confirmed active exploitation of CVE-2026-42945 on 2026-05-17https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html
- thehackernews.cominlineThe Hacker News, 2026-05-23https://thehackernews.com/2026/05/npm-adds-2fa-gated-publishing-and.html
- thehackernews.cominlineThe Hacker News, 2026-05-15https://thehackernews.com/2026/05/on-prem-microsoft-exchange-server-cve.html
- thehackernews.cominlineThe Hacker News, 2026-05-23https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html
- thehackernews.cominlineThe Hacker News — PCPJack credential stealerhttps://thehackernews.com/2026/05/pcpjack-credential-stealer-exploits-5.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/pre-stuxnet-fast16-malware-tampered.html
- thehackernews.cominlineThe Hacker News, 2026-05-14https://thehackernews.com/2026/05/stealer-backdoor-found-in-3-node-ipc.html
- thehackernews.cominlineThe Hacker News, 2026-05-11https://thehackernews.com/2026/05/teampcp-compromises-checkmarx-jenkins.html
- thehackernews.cominlineThe Hacker News, 2026-05-28https://thehackernews.com/2026/05/threat-actors-exploit-critical.html
- thehackernews.cominlineThe Hacker News, 2026-05-25https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html
- thehackernews.cominlineThe Hacker News, 2026-05-04https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html
- thehackernews.cominlineThe Hacker News, 2026-05-19https://thehackernews.com/2026/05/vm2-nodejs-library-vulnerabilities.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/autojack-attack-lets-one-web-page.html
- thehackernews.cominlineThe Hacker News, 2026-06-03https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/china-linked-jdy-botnet-expands-to-1500.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/china-linked-sprysocks-backdoor-expands.html
- thehackernews.cominlineThe Hacker News, 2026-06-04https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html
- thehackernews.cominlineThe Hacker News, 2026-06-16https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/critical-wp-maps-pro-flaw-actively.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/crypto-clipper-campaign-abuses-fake.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/dashlane-discloses-brute-force-attack.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html
- thehackernews.cominlineThe Hacker News, 2026-06-05https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html
- thehackernews.cominlineThe Hacker News, 2026-06-04https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html
- thehackernews.cominlineThe Hacker News, 2026-06-23https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/github-to-disable-npm-install-scripts.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html
- thehackernews.cominlineThe Hacker News, 2026-06-16https://thehackernews.com/2026/06/google-vertex-ai-sdk-flaw-let-attackers.html
- thehackernews.cominlineThe Hacker News, 2026-06-05https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html
- thehackernews.cominlineThe Hacker News, 2026-06-09https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/inc-ransomware-claims-830-victims-since.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/langgraph-flaw-chain-exposes-self.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/malicious-npm-packages-pose-as-postcss.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html
- thehackernews.cominlineThe Hacker News, 2026-06-17https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/microsoft-details-windows-clipper.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/north-korean-hackers-are-turning.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html
- thehackernews.cominlineThe Hacker News — AUR wavehttps://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
- thehackernews.cominlineThe Hacker News, 2026-06-19https://thehackernews.com/2026/06/salesforce-disables-klue-app.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/servicenow-flaw-exploited-to-gain.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/shapedplugin-wordpress-pro-plugins.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/unpatched-windows-search-uri.html
- thehackernews.cominlineThe Hacker News, 2026-06-09https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html
- thehackernews.cominlineThe Hacker News, 2026-06-23https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html
- thehackernews.cominlineThe Hacker News, 2026-06-09https://thehackernews.com/2026/06/winrar-flaw-exploited-by-russia-aligned.html
- thenextweb.cominlineThe Next Webhttps://thenextweb.com/news/gravity-smtp-wordpress-plugin-vulnerability-cve-2026-4020-api-keys-exploit
- therecord.mediainlineThe Recordhttps://therecord.media/canadian-man-arrested-charged-running-kimwolf-botnet
- therecord.mediainlineThe Recordhttps://therecord.media/fbi-warns-of-kali365-phishing-attacks
- therecord.mediainlineThe Recordhttps://therecord.media/five-eyes-warns-chinese-spies-are-using-job-sites-to-recruit-insiders
- therecord.mediainlineThe Record, 2026-05-20https://therecord.media/github-confirms-teampcp-hack-customers-unaffected
- therecord.mediainlineThe Record, 2026-05-06https://therecord.media/hackers-compromise-daemon-tools-global-supply-chain-attack
- therecord.mediainlineThe Record — Huawei VRP / POST Luxembourghttps://therecord.media/huawei-zero-day-behind-last-year-luxembourg-telecom-outage
- therecord.mediainlineThe Recordhttps://therecord.media/mackay-sugar-cyberattack-claimed-gentlemen
- therecord.mediainlineThe Record, 2026-05-29https://therecord.media/microsoft-calls-zero-day-releases-never-justifiable-as-researcher-threatens-more
- therecord.mediainlineThe Record, 2026-05-19https://therecord.media/microsoft-disrupts-fox-tempest-malware-signing-service
- therecord.mediainlineThe Record, 2026-05-15https://therecord.media/more-than-10-million-stolen-crypto-platform-thorchain
- therecord.mediainlineThe Record, 2026-05-14https://therecord.media/openai-asks-macos-users-to-update-tanstack-npm
- therecord.mediainlineThe Record, 2026-06-11https://therecord.media/university-of-nottingham-cyber-incident-shiny-hunters
- theregister.cominlineThe Register, 2026-02-27https://www.theregister.com/2026/02/27/odido_shinyhunters_leaks/
- theregister.cominlineThe Register, 2026-05-11https://www.theregister.com/ai-ml/2026/05/11/google-says-criminals-used-ai-built-zero-day-in-planned-mass-hack-spree/5237982
- theregister.cominlineThe Register, 2026-05-12https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-claims-apple-nvidia-data-theft/5239144
- theregister.cominlineThe Register, 2026-05-18https://www.theregister.com/cyber-crime/2026/05/18/grafana-labs-admits-attackers-downloaded-its-codebase-from-github/5241686
- theregister.cominlineThe Registerhttps://www.theregister.com/cyber-crime/2026/05/22/fbi-warns-of-kali365-as-device-code-phishing-soars/5245024
- theregister.cominlineThe Register, 2026-05-13https://www.theregister.com/patches/2026/05/13/doozy-of-a-patch-tuesday-includes-30-critical-microsoft-cves/5239224
- theregister.cominlineThe Registerhttps://www.theregister.com/patches/2026/06/15/cisco-sd-wan-make-me-root-bug-under-attack/5255916
- theregister.cominlineThe Register, 2026-05-11https://www.theregister.com/security/2026/05/11/best-western-hotels-confirms-web-app-data-breach/5238020
- theregister.cominlineThe Register, 2026-05-12https://www.theregister.com/security/2026/05/12/double-canvas-intrusion-confirmed-as-shinyhunters-resets-leak-deadline/5238361
- theregister.cominlineThe Register, 2026-05-13https://www.theregister.com/security/2026/05/13/disgruntled-researcher-releases-two-more-microsoft-zero-days/5239758
- theregister.cominlineThe Register, 2026-05-19https://www.theregister.com/security/2026/05/19/drupal-warns-admins-to-brace-for-highly-critical-core-patch/5242728
- theregister.cominlineThe Registerhttps://www.theregister.com/security/2026/05/21/cisco-serves-up-yet-another-perfect-10-bug-with-secure-workload-admin-flaw/5244012
- theregister.cominlineThe Registerhttps://www.theregister.com/security/2026/06/11/nightmare-eclipse-drops-claimed-bitlocker-bypass-for-microsoft-windows/5254371
- thezdi.cominlineZDI, 2026-05-12https://www.thezdi.com/blog/2026/5/12/the-may-2026-security-update-review
- thezdi.cominlineZero Day Initiative — Day 1, 2026-05-13https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-day-one-results
- thezdi.cominlineZero Day Initiativehttps://www.thezdi.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results
- thezdi.cominlineZero Day Initiative — Day 3, 2026-05-16https://www.thezdi.com/blog/2026/5/16/pwn2own-berlin-2026-day-three-results-and-master-of-pwn
- threatdown.cominlineMalwarebytes ThreatDownhttps://www.threatdown.com/blog/prinz-eugen-ransomware-a-deep-dive-into-a-new-go-based-encryptor/
- threatfabric.cominlineThreatFabrichttps://www.threatfabric.com/blogs/own-goal-piracy-as-an-attack-vector-to-target-football-fans
- threatlocker.cominlineThreatLocker — exploitation on fully-patched systemshttps://www.threatlocker.com/blog/miniplasma-windows-privilege-escalation-zero-day-affects-fully-patched-systems
- trendmicro.cominlineTrend Microhttps://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html
- trendmicro.cominlineTrend Micro, 2026-06-08https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html
- trmlabs.cominlineTRM Labs, 2026-05-15https://www.trmlabs.com/resources/blog/thorchain-exploit-drains-usd-11m-across-at-least-nine-chains-what-trm-knows-now
- troyhunt.cominlineTroy Hunt's Weekly Update 505, 2026-05-24https://www.troyhunt.com/weekly-update-505/
- ubuntu.cominlineCanonical / Ubuntu advisory bloghttps://ubuntu.com/blog/ssh-keysign-pwn-linux-vulnerability-fixes-available
- ubuntu.cominlineUbuntu Security trackerhttps://ubuntu.com/security/CVE-2026-23111
- unit42.paloaltonetworks.cominlineUnit 42https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/
- unit42.paloaltonetworks.cominlineUnit 42 — Captive Portal zero-dayhttps://unit42.paloaltonetworks.com/captive-portal-zero-day/
- unit42.paloaltonetworks.cominlineUnit 42, 2026-06-22https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/
- unit42.paloaltonetworks.cominlineUnit 42, 2026-06-09https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/
- unit42.paloaltonetworks.cominlineUnit 42https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/
- unit42.paloaltonetworks.cominlineUnit 42 — Copy Failhttps://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/
- unit42.paloaltonetworks.cominlineUnit 42, 2026-06-02https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/
- unit42.paloaltonetworks.cominlinePalo Alto Networks Unit 42, 2026-05-15https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/
- unit42.paloaltonetworks.cominlineUnit 42 — Vertex AIhttps://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/
- unit42.paloaltonetworks.cominlineUnit 42 — Microsoft Teams phishinghttps://unit42.paloaltonetworks.com/microsoft-teams-phishing/
- unit42.paloaltonetworks.cominlineUnit 42 — monitoring npm supply-chain attackshttps://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/
- unit42.paloaltonetworks.cominlineUnit 42 (Palo Alto Networks)https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/
- unit42.paloaltonetworks.cominlineUnit 42 — ROADtools cloud attackshttps://unit42.paloaltonetworks.com/roadtools-cloud-attacks/
- unit42.paloaltonetworks.cominlineUnit 42 — Screening Serpenshttps://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/
- varonis.cominlineVaronishttps://www.varonis.com/blog/openclaw-phishing
- varonis.cominlineVaronis Threat Labshttps://www.varonis.com/blog/searchleak
- veeam.cominlineVeeam KB4852https://www.veeam.com/kb4852
- veeam.cominlineVeeam, 2026-06-09https://www.veeam.com/kb4869
- verizon.cominlineVerizon — 2026 DBIR announcementhttps://www.verizon.com/about/news/breach-industry-wide-dbir-finds
- verizon.cominlineVerizon DBIR pagehttps://www.verizon.com/business/resources/reports/dbir/
- vimeo.cominlineVimeo official blog — Anodot incidenthttps://vimeo.com/blog/post/anodot-third-party-security-incident
- volexity.cominlineVolexity — OAuth device-code backgroundhttps://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/
- volexity.cominlineVolexityhttps://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/
- welivesecurity.cominlineESET WeLiveSecurity — APT Activity Report Q4 2025–Q1 2026https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/
- welivesecurity.cominlineESET, 2026-06-24https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/
- welivesecurity.cominlineESET WeLiveSecurityhttps://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/
- welivesecurity.cominlineESET WeLiveSecurityhttps://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
- wid.cert-bund.deinlineBSI WID-SEC-2026-1536, 2026-05-14https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1536
- wid.cert-bund.deinlineBSI WID-SEC-2026-1579https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1579
- wid.cert-bund.deinlineBSI WID-SEC-2026-1583, 2026-05-19https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1583
- wid.cert-bund.deinlineBSI WID-SEC-2026-1716https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1716
- wid.cert-bund.deinlineBSI CERT-Bund WID-SEC-2026-1724https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1724
- wid.cert-bund.deinlineBSI CERT-Bund WID-SEC-2026-1740https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1740
- wid.cert-bund.deinlineBSI CERT-Bund WID-SEC-2026-1778https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1778
- wid.cert-bund.deinlineBSI CERT-Bund WID-SEC-2026-1800https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1800
- wid.cert-bund.deinlineBSI CERT-Bund, 2026-06-09https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1832
- wid.cert-bund.deinlineBSI CERT-Bund WID-SEC-2026-1989https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1989
- wid.cert-bund.deinlineBSI CERT-Bund WID-SEC-2026-2002https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2002
- wid.cert-bund.deinlineBSI WID-SEC-2026-2027https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2027
- wiz.ioinlineWiz Researchhttps://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc
- wiz.ioinlineWiz, 2026-05-20https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack
- wiz.ioinlineLinux kernel security advisory CVE-2026-46300https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp
- wiz.ioinlineWiz Researchhttps://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages
- wiz.ioinlineWiz Bloghttps://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
- wiz.ioinlineWiz Research — Mini Shai-Hulud hits @antvhttps://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain
- wiz.ioinlineWiz Research — JINX-0164https://www.wiz.io/blog/threat-actors-target-crypto-orgs
- wordfence.cominlineWordfencehttps://www.wordfence.com/blog/2026/06/attackers-actively-exploiting-critical-vulnerability-in-everest-forms-pro-plugin/
- wordfence.cominlineWordfencehttps://www.wordfence.com/blog/2026/06/psa-supply-chain-compromise-targets-shapedplugin-backdoored-pro-plugins-distributed-via-official-channels/
- wpscan.cominlineWPScanhttps://wpscan.com/vulnerability/68addf8c-9ea6-4b62-9f85-e95350b3992e/
- xbow.cominlineXBOW research, 2026-05-12https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim
- yeswehack.cominlineYesWeHack technical write-uphttps://www.yeswehack.com/news/rce-joomla-content-editor-extension
- zeroday.cloudinlineZeroDay.Cloud, 2026-06-02https://www.zeroday.cloud/blog/redis-cve-2026-23479-deep-dive
- zerodayinitiative.cominlineZero Day Initiative, 2026-05-15https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results
- zerofox.cominlineZeroFox Q1 2026 Wrap-Up, 2026-04-17https://www.zerofox.com/intelligence/q1-2026-ransomware-wrap-up/
- zetter-zeroday.cominlineKim Zetter / ZERO DAYhttps://www.zetter-zeroday.com/experts-confirm-the-fast16-malware-was-sabotaging-nuclear-weapons-tests-likely-in-iran/
- zimperium.cominlineZimperium zLabs, 2026-06-16https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities
- zscaler.cominlineZscaler ThreatLabz — Payouts King / Edgecutionhttps://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution