[Control systems] ABB security advisory (AV26-580)
Jenkins security advisory (AV26-578)
FreePBX security advisory (AV26–579)
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. [...]
The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain attacks, was briefly open-sourced on GitHub. [...]
Your pentest report looks clean. That might be the problem. Run automated pentesting long enough, and the new findings start to dry up. By the third or fourth run, fewer issues appear. The report...
GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the 'npm install'...
Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors
Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that have been publicly disclosed at the time of release. Of...
AMD security advisory (AV26-577)
FreeBSD security advisory (AV26-576)
Mozilla security advisory (AV26-575)
HPE security advisory (AV26-573)
Spring security advisory (AV26-574)
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. [...]
OpenSSL security advisory (AV26-572)
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment...
For the past several years, the technology sector has remained the most targeted sector by eCrime and state-sponsored adversaries. The persistent volume of hands-on-keyboard intrusions targeting...
The ACLU is suing two Florida police departments over the arrest of a Fort Myers man in a child-abduction case, saying officers treated a flawed face recognition match as a near-certain ID.
In the latest sign that unmanned vehicles are an increasingly pivotal part of a modern military, a drone boat rescued the two-person crew from the U.S. Apache helicopter gunship that went down...
The Cybersecurity and Infrastructure Security Agency is extending nearly 200 job offers this month, as CISA looks to reinforce its depleted ranks amid a wave of new artificial intelligence...
Anthropic is releasing a straitjacketed version of Mythos that researchers believe is safe for widespread use and relies on older technology for some of what it does, the company said on Tuesday....
Trump administration officials have asked a government artificial intelligence testing unit to stop issuing public reports, the latest signal that the White House is tightening control over AI...
On June 9, Anthropic released Claude Fable 5, the most capable model it has ever made, generally available. It also did something unusual: it shipped one model as two products, split not by...
Remote, unauthenticated RCE with root privileges is about as bad as it gets
The release comes after Microsoft’s security leadership acknowledged last month that AI tools are driving a surge in vulnerability discovery across the industry.
ServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to susceptible instances. "On June 5, 2026, ServiceNow applied...
Missing Authentication for Critical Function vulnerability (CVE-2026-8335) has been found in Aix-DB software.
New research from CYFIRMA identified that energy and utilities organizations remain firmly in the sights of nation-state cyber... The post Energy and utilities sector targeted in 66% of observed...
New data from Fortinet‘s 2025 State of Operational Technology and Cybersecurity Report found that industrial organizations are steadily... The post OT cybersecurity becomes a board-level priority...