SecurityWeek
securityweek · B · active
Industry news; verify primary source. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.securityweek.com/ (homepage listing) then webfetch the per-article slug for body. AVOID: Nothing — webfetch works on homepage and articles; just verify the primary source it cites per its MEDIUM tier. | 2026-07-05 admiralty audit: B (up from MEDIUM) — established staffed security journalism with original reporting + editorial process; still trace vendor-sourced items to primary. Status stays active.
Cited in 86 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 46).
- Water-utility PLC lockouts reach at least twelve US states, and Clayton County publicly confirms a distribution-side consequence as its own2026-08-06
- SonicWall SMA 1000 (CVE-2026-15409/-15410) escalation: Rapid7 calls INC Ransom the dominant actor on the chain, and says it watched the actor roll an applied patch back to stay in2026-08-04
- Water-sector PLC lockouts went from one state to seven inside the week, and the European exposure got counted — 86% of 4,117 internet-facing Siemens S7-1200 units sit in four EU countries, reached through mobile carriers2026-08-02
- This week's tradecraft was built against the analyst's environment, not the endpoint agent — samples that refuse to run without a keyed argument, loaders that cannot decrypt away from the host they infected, and operators driving the victim's own logged-in session2026-08-02
- Water-utility PLC lockouts spread to seven US states — FBI names the targeted controllers, and a Censys scan puts 86% of exposed Siemens S7-1200 units in four European countries2026-08-01
- MedusaHVNC: a malware-as-a-service RAT that drives the victim's own logged-in browser on an invisible second Windows desktop2026-07-28
- CVE-2026-63030 / CVE-2026-60137 (WP2Shell) — WordPress Core pre-auth RCE chain moves to confirmed in-the-wild exploitation and CISA KEV2026-07-26
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection2026-07-21
- CVE-2026-42533 — nginx / NGINX Plus: PCRE capture-clobber pre-auth heap overflow, researcher demonstrates RCE beyond F5's DoS-only framing (CVSS 9.2)2026-07-20
- SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud — two reachable without authentication2026-07-14
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed2026-07-13
- CVE-2026-20896 — NCSC-CH escalates the Gitea Docker reverse-proxy auth bypass to 'actively exploited'2026-07-10
- ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces2026-07-05
- Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign2026-07-01
- Aflac discloses a Japan-subsidiary breach — 4.38 million policyholders and agents, ~10-day dwell before detection2026-07-01
- US posts $10M bounty on the Russia-nexus Signal/WhatsApp crews and adds Signal Backup-Recovery-Key theft to the advisory2026-06-30
- Technology & SaaS supply chain — the week's busiest victim class2026-06-29
- ShinyHunters / UNC6240 Oracle PeopleSoft campaign2026-06-29
- Looking ahead — 2026-W262026-06-29
- Klue / Icarus Salesforce OAuth-integration breach — from nine named victims to ~24, then the attacker gets hacked2026-06-29
- CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)2026-06-29
- Klue/Icarus Salesforce breach widens to ~24 firms; the attacker is itself hacked and a second extortion actor emerges2026-06-27
- "Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke2026-06-25
- Klue/Icarus Salesforce OAuth breach — BeyondTrust and LastPass added to the named-victim list2026-06-25
- "Cordyceps" — the GitHub Actions pull_request_target pwn-request class is still widely exploitable at scale2026-06-25
- CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV2026-06-24
- "Squidbleed" — a 29-year-old heap over-read in Squid's FTP gateway leaks other users' cleartext HTTP credentials (CVE-2026-47729)2026-06-23
- Klue/Icarus OAuth-token breach — named victim list expands to nine firms, mostly cybersecurity vendors2026-06-23
- FortiBleed — first full tool-chain disclosure (FortigateSniffer, SNIFTRAN, GPU cracking cluster); Fortinet confirms no new CVE2026-06-23
- ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure2026-06-22
- Public administration — named European institutions and government data in the firing line2026-06-22
- Looking ahead — 2026-W252026-06-22
- FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory2026-06-22
- CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)2026-06-22
- CVE-2026-20253 — Splunk Enterprise pre-auth RCE flips to confirmed exploitation and CISA KEV2026-06-22
- Splunk CVE-2026-20253 now under confirmed limited targeted exploitation2026-06-20
- Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication2026-06-20
- FortiBleed reaches 86,644 compromised FortiGate devices; CISA issues emergency hardening guidance2026-06-20
- CVE-2026-42530 / CVE-2026-42055 — NGINX: HTTP/3 QUIC use-after-free and HTTP/2-proxy heap overflow, out-of-band F5 patches2026-06-19
- CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution2026-06-19
- Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane2026-06-19
- CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (CVSS 10.0) and PeopleSoft RCE (9.8)2026-06-18
- PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule2026-06-16
- Council of Europe named as a victim of the Oracle PeopleSoft (CVE-2026-35273) campaign2026-06-16
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform — billing PII for ~2M customers leaked, no OT access2026-06-15
- Looking ahead — 2026-W242026-06-14
- Chaotic Eclipse / Nightmare Eclipse Windows zero-day wave — three long-tracked bugs patched, a fourth still open2026-06-14
- ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records2026-06-12
- "GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition — PoC public, practical severity contested2026-06-12
- "RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch2026-06-11
- CVE-2026-10881 — Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)2026-06-07
- GMO Flatt Security: one GitHub issue could hijack any public repo running Anthropic's claude-code-action — and could have poisoned the action itself2026-06-05
- Symantec: five-month, low-and-slow mailbox-espionage campaign against a global stock exchange2026-06-04
- Enclave: a single debug flag left on in six Microsoft 365 Android apps allowed silent OAuth-token theft2026-06-04
- CVE-2026-8206 + CVE-2026-8181 — Kirki and Burst Statistics WordPress plugins: unauthenticated account takeover under active mass-exploitation2026-06-04
- CVE-2026-49975 — HTTP/2 Bomb: HPACK amplification + Slowloris chains to single-connection RAM exhaustion, patch status split by server2026-06-01
- GREYVIBE — newly documented Russia-nexus cluster deploys five parallel attack chains against Ukraine with AI-generated lures and two PowerShell RATs2026-05-30
- "Underminr": a multi-tenant-CDN domain-fronting variant that blinds DNS-layer filtering2026-05-25
- GREYVIBE — independent corroboration; OPSEC slips enabled attribution; charity-front sub-campaign2026-05-25
- Drupal SA-CORE-2026-004 / CVE-2026-9082 ships — "highly critical" pre-auth SQL injection in core database API, PostgreSQL-only2026-05-21
- + 26 earlier entries