SecurityWeek
securityweek · B · active
Industry news; verify primary source. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.securityweek.com/ (homepage listing) then webfetch the per-article slug for body. AVOID: Nothing; webfetch works on homepage and articles; just verify the primary source it cites per its MEDIUM tier. | 2026-07-05 admiralty audit: B (up from MEDIUM), established staffed security journalism with original reporting + editorial process; still trace vendor-sourced items to primary. Status stays active.
Cited in 61 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 46).
- CVE-2026-84869, ConnectWise ScreenConnect: a missing file-transfer authorization check lets an active remote session push and auto-run files on the Host, and Huntress traced worm-like exploitation back to 20 August, weeks before any patch existed (CVSS 9.9)2026-09-12
- Ivanti September 2026 Security Update, ten CVEs across Neurons for ITSM, Sentry and EPMM, two unauthenticated CVSS 9.8 deserialization RCEs2026-09-11
- A dark-web identity-theft storefront sells 153 million+ driver's-license scans traced to identity-verification vendor IDScan.net; FBI opens a formal investigation2026-09-06
- CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000: a pre-auth SSRF through an undocumented Work Place access path chains into post-auth command injection in the Management Console) both under active exploitation2026-09-03
- CVE-2026-82329, JFrog Artifactory: an unauthenticated attacker gets administrative access under default configuration (CVSS 9.8)2026-09-01
- CVE-2026-21962: an unauthenticated request bypasses access control in the Oracle WebLogic Server Proxy Plug-in, CISA KEV-listed on 24 August with exploitation running since January2026-08-30
- Oracle's August 2026 Critical Security Patch Update carries three unauthenticated CVSS 10.0 flaws, one of them in the LDAP server of Oracle Internet Directory2026-08-20
- CVE-2026-19478; GitLab ships an out-of-band critical patch for a GraphQL directive flaw that lets an unauthenticated caller modify or delete public projects and user data (CVSS 9.4)2026-08-19
- The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned2026-08-15
- GeoServer: an unauthenticated SQL injection in the jsonArrayContains filter is being exploited with no CVE and no patch, and NCSC-CH has put it in front of Swiss operators2026-08-15
- CVE-2026-26035, FortiWeb: one non-default RADIUS admin setting turns any username and password into a valid GUI/CLI login, alongside an FGFM impersonation bug and a FortiClient flaw reachable by anyone who can answer a laptop's DNS2026-08-15
- Belgium's eID signing extension handed any web page the card, the PIN and a drive-by RCE, an eIDAS Qualified Trust Service Provider's browser bridge that never checked the caller's origin2026-08-11
- Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities; no authority has attributed it2026-07-29
- MedusaHVNC: a malware-as-a-service RAT that drives the victim's own logged-in browser on an invisible second Windows desktop2026-07-28
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection2026-07-21
- CVE-2026-42533, nginx / NGINX Plus: PCRE capture-clobber pre-auth heap overflow, researcher demonstrates RCE beyond F5's DoS-only framing (CVSS 9.2)2026-07-20
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term2026-07-18
- CVE-2026-15409, SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited2026-07-14
- SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud, two reachable without authentication2026-07-14
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat', day three, no patch or root cause disclosed2026-07-13
- Aflac discloses a Japan-subsidiary breach, 4.38 million policyholders and agents, ~10-day dwell before detection2026-07-01
- NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause2026-06-28
- FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover2026-06-27
- "Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke2026-06-25
- "Cordyceps"; the GitHub Actions pull_request_target pwn-request class is still widely exploitable at scale2026-06-25
- CVE-2025-67038, Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV2026-06-24
- "Squidbleed", a 29-year-old heap over-read in Squid's FTP gateway leaks other users' cleartext HTTP credentials (CVE-2026-47729)2026-06-23
- CVE-2026-20896, Gitea (Docker): trust-all reverse-proxy default lets an unauthenticated attacker impersonate any user via X-WEBAUTH-USER2026-06-23
- Klue OAuth-token breach, victim list grows, CRM-API abuse chain detailed2026-06-21
- Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication2026-06-20
- CVE-2026-42530 / CVE-2026-42055, NGINX: HTTP/3 QUIC use-after-free and HTTP/2-proxy heap overflow, out-of-band F5 patches2026-06-19
- CVE-2026-20181 / CVE-2026-20190, Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution2026-06-19
- Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane2026-06-19
- FortiBleed, 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory2026-06-18
- CVE-2026-46978 / CVE-2026-35278, Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (CVSS 10.0) and PeopleSoft RCE (9.8)2026-06-18
- PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule2026-06-16
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform, billing PII for ~2M customers leaked, no OT access2026-06-15
- CVE-2026-20253, Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy2026-06-14
- "GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition, PoC public, practical severity contested2026-06-12
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration2026-06-11
- "RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch2026-06-11
- CVE-2026-10881, Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)2026-06-07
- GMO Flatt Security: one GitHub issue could hijack any public repo running Anthropic's claude-code-action, and could have poisoned the action itself2026-06-05
- Symantec: five-month, low-and-slow mailbox-espionage campaign against a global stock exchange2026-06-04
- Enclave: a single debug flag left on in six Microsoft 365 Android apps allowed silent OAuth-token theft2026-06-04
- CVE-2026-8206 + CVE-2026-8181, Kirki and Burst Statistics WordPress plugins: unauthenticated account takeover under active mass-exploitation2026-06-04
- GREYVIBE, newly documented Russia-nexus cluster deploys five parallel attack chains against Ukraine with AI-generated lures and two PowerShell RATs2026-05-30
- "Underminr": a multi-tenant-CDN domain-fronting variant that blinds DNS-layer filtering2026-05-25
- Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC2026-05-20
- Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected2026-05-19
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic2026-05-19
- CVE-2026-41225, F5 BIG-IP / BIG-IQ: iControl REST Manager-role authenticated RCE (CVSS 4.0 score 8.6 / CVSS 3.1 score 9.1) leading the May 2026 Quarterly Notification2026-05-17
- UAT-8616 exploits Cisco Catalyst SD-WAN CVE-2026-20182; 10+ clusters exploit companion February 2026 CVEs; CISA Emergency Directive ED-26-03 issued2026-05-15
- CVE-2026-8043 Ivanti Xtraction external file control (CVSS 9.6) plus EPM SQL-injection-to-RCE and vTM admin OS-command injection, May 2026 advisory batch, no ITW2026-05-14
- CVE-2026-34263 / CVE-2026-34260, SAP Commerce Cloud pre-auth RCE, S/4HANA Enterprise Search SQL injection2026-05-13
- BWH Hotels (Best Western, WorldHotels, Sure Hotels), 181-day unauthorised access to a guest-reservation web application, six EU brands in scope2026-05-13
- TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner2026-05-12
- Škoda Auto Deutschland online-shop breach exposes customer PII and password hashes; logging gap prevents exfiltration confirmation2026-05-12
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware2026-05-12
- Braintrust AI evaluation platform AWS account breach, multi-tenant LLM-provider keys and SaaS credentials at risk; mandatory key rotation across customer base2026-05-10
- + 1 earlier entries