Mozilla security advisory (AV26-644)
As the time from vulnerability discovery to exploitation shrinks, building with minimal, secured components is more important than ever. Here is how WizOS helps.
The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat...
An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn...
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-35095 to CVE-2026-35098) found in KTM System e-BOK software.
Host Caleb Tolin sits down with Selena Larson, Staff Threat Researcher and Lead, Intelligence Analysis and Strategy at Proofpoint and Host of the DISCARDED podcast, to discuss the mechanics of...
Two researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless...
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-53432 and CVE-2026-53433) found in fzf software.
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
wolfSSL security advisory (AV26-643)
The House passed a sprawling package of kids online safety bills Monday night, marking the first time a version of the landmark Kids Online Safety Act (KOSA) made it out of the lower chamber. The...
Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI...
Key points LevelBlue has identified two distinct attack vectors associated with ValleyRAT: campaigns leveraging fake installers and campaigns initiated through malicious emails. The malicious...
The Washington Department of Social and Health Services (DSHS) is issuing a notice of a massive data breach that happened in March, potentially compromising the personal data of around 8,600...
Critical and high-severity vulnerabilities in some Daktronics controllers could allow hackers to tamper with highway signs and billboards, according to the cybersecurity researcher who discovered...
Vulnerabilities in remote monitoring and management (RMM) tools can give attackers a direct path into enterprise environments, often with the same trusted access that IT administrators rely on to...
The UK’s healthcare sector is being “stress-tested to breaking point,” with a tenfold increase in attacks during January-May 2026 compared to the whole of 2025, according to SonicWall. The...
The U.S. Department of Justice (DOJ) has seized nearly 400 internet domains that were illegally streaming FIFA World Cup 2026 matches. The operation, known as Operation Offsides, targeted websites...
The National Telecommunications and Information Administration (NTIA) has yet to implement most of the Government Accountability Office’s (GAO) priority recommendations for improving the agency’s...
A passenger jet reported striking a drone while approaching JFK International Airport on Monday, and just hours later, a helicopter pilot alerted a close call with a remote-control airplane near...
Russian cybercriminals managed to hack into a Quebec municipality’s water treatment plant systems and had the ability to wreak havoc on the crucial infrastructure before getting caught, according...
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw,...
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-53690 to CVE-2026-53692) found in Redeight CMS software.
On December 20, 2025, the China National Nuclear Corporation (CNNC) announced that Chaotan One, the world’s first commercial supercritical carbon dioxide power generator, began commercial...
Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using...
The Supreme Court on Monday said that police must generally obtain a warrant to gather detailed location data tracked by smartphones, in a case that brings into sharper relief the Constitution’s...
SimpleHelp security advisory (AV26-642)
The Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia. I wrote about this sort of thing a few years...
SQL Injection vulnerability (CVE-2026-12076) has been found in Raytha CMS software.
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score:...