CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA added four vulnerabilities to its KEV catalog, including flaws in Lantronix EDS5000 and Ubiquiti UniFi OS, citing active exploitation.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,755 stories synthesized.
CISA added four vulnerabilities to its KEV catalog, including flaws in Lantronix EDS5000 and Ubiquiti UniFi OS, citing active exploitation.
Key findings • Three Adobe Acrobat Reader vulnerabilities disclosed on June 23, 2026, including one for arbitrary code execution. • Two out-of-bounds read vulnerabilities could lead to sensit…
The U.S. Justice Department seized cloud infrastructure used by Huione Group's criminal marketplace Huione Guarantee, while Treasury sanctioned 26 Prince Group-linked entities, disrupting billions in scam proceeds.
Indian two-wheeler manufacturer Bajaj Auto disclosed a ransomware attack on June 23, 2026, that compromised IT systems at the parent company and its subsidiary Bajaj Auto Technology Ltd.
AWS published an advisory warning that unmonitored outbound traffic in cloud environments creates a blind spot enabling data exfiltration, highlighting CVE-2025-55182 and risks from agentic AI systems.
Key findings • Eight vulnerabilities in Revive Adserver 6.0.6 and earlier disclosed on June 23, 2026. • Flaws include missing access control, enabling unauthorized linking of trackers and ban…
CISA disclosed multiple Linux kernel vulnerabilities, including CVE-2026-31431, impacting B&R Industrial Automation products, with local privilege escalation risk and public PoCs available.
CISA and Siemens disclosed CVE-2025-15467, a critical stack-based buffer overflow in OpenSSL that impacts a vast range of Siemens industrial products, from SCALANCE routers to AI servers, with potential for remote code execution.
CISA disclosed a medium-severity authentication bypass vulnerability in ABB Freelance Security Lock that could let local attackers access underlying OS functions via undocumented key combinations.
CISA disclosed a high-severity vulnerability in Siemens WinCC Certificate Manager that could allow local attackers to extract sensitive key material from industrial systems.
CISA disclosed CVE-2025-40808, a high-severity arbitrary file upload vulnerability in Siemens SIPROTEC 5 relays that could let authenticated attackers achieve code execution and denial of service across critical infrastructure.
CISA disclosed CVE-2026-1840, a high-severity missing authentication vulnerability in Hubbell Aclara Metrum Cellular Web Interface that could let unauthenticated attackers alter critical device settings and trigger system restarts.
CISA disclosed four vulnerabilities in Siemens SINEC INS, including a critical OS command injection flaw allowing authenticated remote code execution on industrial systems.
A Malwarebytes deep-dive into dark web forums and marketplaces uncovered over 1,200 unpublicized data breaches since 2026, with stolen US identities selling for as little as 95¢ and more than 8.4 billion records exposed.
Security firm AIR created a fake AI agent skill that passed every tested security scanner and reached roughly 26,000 agents via a popular marketplace and Instagram ad, exposing critical gaps in AI agent supply chain vetting.
Picus Security details a methodology for security teams to validate exploitability of newly disclosed vulnerabilities before public exploits exist, addressing the widening gap between disclosure and weaponization.
Dragos released EmberAI, an OT-native AI built on its Intelligence Fabric, giving critical infrastructure teams a decade of operational threat data to prioritize vulnerabilities by real-world impact.
Microsoft's DART team uncovered two separate threat actors, including Storm-2603, simultaneously operating inside the same on-premises SharePoint environment, using Velociraptor, Cloudflare tunnels, Zoho Assist, and VS Code SSH for persistence.
A new macOS backdoor called FlutterShell abuses Google's Flutter framework and WKWebView to evade detection, active from December 2025 to March 2026.
The FBI issued a public warning that cybercriminals are using Traffic Distribution Systems to silently redirect users to phishing sites and malware portals, evading security scanners through precise targeting.
A new class of supply-chain vulnerabilities named Cordyceps targets GitHub Actions CI/CD workflows, allowing unauthenticated attackers to take full control of code repositories via a single pull request.
Meta paused its Model Capability Initiative after an internal security review found keystroke, mouse-movement, and screen-capture data from staff laptops was accessible across thousands of internal data tables.
A high-severity use-after-free vulnerability in Samsung's KNOX security framework, present for eight years, exposed millions of Galaxy devices to kernel-level attacks.
Key findings • Five CVEs disclosed June 21–23, 2026, affecting ImageMagick 7.1.x and 6.9.x • CVE-2026-56379 is a command injection in the SVG decoder via MVG commands • Two heap out-of-…