Apple Seeds iPadOS 27.0 Beta 2 to Developers with Security Fixes
Apple released iPadOS 27.0 beta 2 (build 24A5370h) for developer testing, with security fixes expected to be detailed at final release.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,764 stories synthesized.
Apple released iPadOS 27.0 beta 2 (build 24A5370h) for developer testing, with security fixes expected to be detailed at final release.
Gizmodo confirmed a security incident on Saturday after readers encountered ClickFix malware prompts on article pages, attributed to an ErrTraffic affiliate.
A new report from BindingHook reveals that Chinese state-sponsored cyber operations rely on a commercial ecosystem of private contractors, botnet operators, and data brokers, a model termed 'composite responsibility.'
Canada's spy agency, CSIS, secured a novel threat reduction warrant to remotely disinfect servers, home routers, and IoT devices infected by two foreign-run botnets, marking a legal and operational first for domestic cyber defense.
Cornell Tech researchers disclose WARP, a novel attack that uses a single Reddit comment to poison AI deep-research agents like ChatGPT and Gemini.
Researchers discovered 23 malicious plugins on the ClawHub AI agent registry that exploited unreserved official scopes to execute arbitrary code within Claude and OpenClaw agents.
Elastic Security Labs has uncovered OXLOADER, a novel loader distributed through Google Ads that impersonates the Node.js installer to deploy the CASTLESTEALER infostealer on Windows systems.
Key findings • Three CVEs disclosed together for Apache NiFi on June 22, 2026, affecting versions up to 2.9.0 • CVE-2026-44911 (CVSS 8.8) lets read-only users invoke privileged configuration …
Researchers uncovered a coordinated campaign where attackers compromised over 10,000 GitHub repositories by cloning legitimate projects and injecting malicious links in README files, distributing Trojan malware families like SmartLoader and StealC.
INTERPOL's 2025/2026 report warns of a dramatic rise in cybercrime across Asia and the South Pacific, driven by AI-powered scams, ransomware-as-a-service, and rapid digitalization.
Key findings • 25 CVEs across 23 WordPress plugins disclosed June 19–22, 2026 • Critical unauthenticated file deletion in Avada Builder (CVE-2026-8713, CVSS 9.1) affects ~1M sites • Thr…
During an authorized red-team evaluation, Anthropic's Mythos AI model reportedly infiltrated nearly all NSA classified systems within hours, prompting unprecedented US export controls on AI models.
Asymptote Labs has released Agent Beacon, an open-source telemetry layer that monitors AI coding agents across developer laptops, CI jobs, and cloud environments, providing security teams with normalized visibility into agent behavior.
New research shows that DNS-over-TLS, HTTPS, and QUIC expose DNS flows via plaintext packet headers, enabling eavesdroppers to identify and exploit IoT device traffic.
Researchers found 282 of 444 iOS apps with LLM features exposed exploitable credentials or backend access, affecting popular apps across 13 categories.
The release of systemd 261 adds a software-based TPM, a cloud instance metadata subsystem, process state persistence across kexec reboots, and a new operating system installer, impacting nearly all modern Linux distributions.
Key findings • Ten vulnerabilities in Libexpat disclosed on June 21, 2026, all fixed in version 2.8.2. • A majority of the CVEs are integer overflows in various parsing functions. • CVE-2…
A new botnet named AryStinger has infected over 4,000 D-Link routers, primarily DIR-850L and DIR-818LW models, exploiting old vulnerabilities to turn them into proxies for malicious traffic.
Key findings • Nine vulnerabilities disclosed for Craft CMS and Craft Commerce between June 19-21, 2026. • Flaws include RCE, SSRF, path traversal, authorization bypass, and multiple stored X…
Key findings • Ten vulnerabilities in Litellm disclosed on June 21, 2026, affecting versions up to 1.82.5. • Key issues include improper authorization, server-side request forgery (SSRF), and…
A weekly roundup highlights two major security incidents: 74,000 Fortinet firewall credentials were stolen, and a remote code execution vulnerability in Splunk Enterprise is under active attack.
Key findings • CVE-2026-56346 allows unauthenticated PGP message decryption via decryptMessage.json.php • CVE-2026-56345 enables arbitrary user session hijacking through the Meet plugin •…
CyberSentinel AI v3.0 integrates 33 cybersecurity tools like Nmap and SQLMap with a provider-agnostic AI engine supporting Claude, GPT-4o, and fully offline local inference using Ollama.
Key findings • 21 CVEs disclosed together on June 19–20, 2026, all patched in versions 12.128.2 and 12.128.12 • Four unauthenticated cross-tenant bugs target Supabase PostgREST RPC function…