Security news, decoded.
75 stories in the last 7 days, naming 205 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Tuesday, Jun 3014 stories
- The Hacker NewsLangflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Attackers are exploiting CVE-2026-33017, an unauthenticated remote code execution issue in Langflow (CVSS 9.3), to gain initial access on internet-exposed AI application endpoints. Once triggered, the flaw enables deployment of a Monero cryptocurrency miner that disables host security components, persists via scheduling/cron, spreads through reused SSH credentials, and attempts to erase evidence. This matters because it turns reachable Langflow instances into a new entry point for commodity cryptojacking into enterprise environments.
Reported exploitedLangflow - Help Net SecurityOracle E-Business Suite Payments flaw under attack (CVE-2026-46817)
Threat actors have been observed attempting exploitation of CVE-2026-46817 against Oracle Payments, the payment-processing module in Oracle’s E-Business Suite (EBS). The issue targets the ibytransmit endpoint in Oracle Payments’ File Transmission component and can be used by unauthenticated remote attackers to read files from the server, potentially exposing sensitive data such as database credentials, encryption keys, and API secrets. Oracle patched the vulnerability in late May 2026, and organizations running Oracle E-Business Suite versions 12.2.3 to 12.2.15 should apply the May 2026 Critical Security Patch Update immediately and avoid public internet exposure of EBS web interfaces until updated.
Reported exploitedOracle E-Business Suite - SecurityWeekBlueHammer Vulnerability Exploited in Ransomware Attacks
CISA says a vulnerability in Microsoft Defender, tracked as BlueHammer and identified as CVE-2026-33825, is being used as part of ransomware intrusions. The issue affects Microsoft’s Defender component and can enable authenticated attackers to escalate privileges, which is why it matters for incident risk. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and later updated the entry to indicate ransomware exploitation in the wild, underscoring the need to apply Microsoft’s April patches.
Reported exploitedMicrosoft Defender - SecurityWeekExploitation of Recent Oracle E-Business Suite Vulnerability Begins
Threat actors have begun targeting a critical Oracle E-Business Suite (EBS) vulnerability tracked as CVE-2026-46817 (CVSS 9.8), with activity observed against the File Transmissions component in the Payments product. Oracle says unauthenticated attackers can exploit the issue over HTTP to take over Oracle Payments, making it a high-impact risk for organizations running EBS. The flaw was addressed in Oracle’s first monthly Critical Security Patch Update (CSPU) in late May, so defenders should prioritize patching to reduce exposure.
Reported exploitedOracle E-Business Suite - The Hacker NewsAttackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
An unidentified threat actor is actively exploiting the critical SimpleHelp flaw CVE-2026-48558 (CVSS 10.0), which allows an unauthenticated attacker to bypass authentication in OpenID Connect (OIDC) flows and obtain a fully authenticated “Technician” session. Using that access, they deployed two malware families, TaskWeaver (a Node.js loader) and Djinn Stealer (a cross-platform credential and data-stealing payload targeting systems across Windows, macOS, and Linux). The scale of harvested secrets—spanning cloud accounts, code repositories, AI tooling, and cryptocurrency wallets—makes this a high-impact risk, and CISA has added CVE-2026-48558 to its Known Exploited Vulnerabilities catalog.
Reported exploitedSimpleHelp RMM - Help Net SecuritySimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)
Attackers are actively exploiting CVE-2026-48558, a newly fixed authentication bypass in SimpleHelp RMM, to gain access and deploy Djinn Stealer on compromised systems. The malware is reported to target Windows, macOS, and Linux and can harvest credentials and sensitive data from many cloud platforms, development tools, browsers, SSH, and cryptocurrency wallets. This matters because stolen tokens, keys, and session data could enable re-entry and further compromise even after the original SimpleHelp server is isolated.
Reported exploitedSimpleHelp RMM - SANS Internet Storm CenterJune 2026 Apple Updates - SANS Internet Storm Center
Apple released security updates for iOS/iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, addressing multiple vulnerabilities that primarily impact browser components such as WebKit, libxslt, WebRTC, and Web Extensions. CVE-2026-39868, CVE-2026-43676, CVE-2026-43700, CVE-2026-43701, CVE-2026-43703, CVE-2026-43704, CVE-2026-43705, CVE-2026-43706, CVE-2026-43707, CVE-2026-43708, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43718, CVE-2026-43720, CVE-2026-43721, CVE-2026-43722, CVE-2026-43724, CVE-2026-43725, CVE-2026-43727, CVE-2026-43732, CVE-2026-43735, CVE-2026-43740, CVE-2026-43742, CVE-2026-43743, CVE-2026-43745, CVE-2026-43746, and CVE-2026-43732 are included, with additional issues in the Kernel and IOGPUFamily. None of the reported flaws are labeled as “exploited,” but the browser-focused nature makes timely patching important.
PatchiOS - The Hacker NewsAirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
Researchers reported six vulnerabilities across Apple AirDrop and Samsung Quick Share that let an attacker nearby disrupt the receiving service (crashing sharingd on macOS/iOS) without user interaction, potentially affecting multiple Continuity-related features at once. For Quick Share, Samsung’s Android issues can bypass session handshake checks, while Google’s Quick Share for Windows contains a memory safety problem consistent with a use-after-free, with a CVE still pending; the component has previously been linked to CVE-2024-38271, CVE-2024-38272, and CVE-2024-10668. The findings matter because these flaws require only local proximity or a shared network, meaning attackers in crowded locations could impact many nearby devices.
ResearchAirDrop - SecurityWeekNissan Employee Data Breached in Oracle PeopleSoft Hack
Nissan reported that employee data was exposed as part of a zero-day campaign aimed at Oracle PeopleSoft environments. The incident affected Nissan Americas, which uses Oracle PeopleSoft for functions including tax and payroll processing, with the exploited issue tracked as CVE-2026-35273. The company suspects attackers accessed information such as SSNs, banking details, and financial or tax records for current and former employees across multiple countries, underscoring the risk of widely targeted enterprise software flaws.
Reported exploitedOracle PeopleSoft - BleepingComputerCISA: Windows BlueHammer flaw now exploited by ransomware gangs
The U.S. CISA has confirmed that ransomware groups have started exploiting the Microsoft Defender privilege-escalation vulnerability tracked as CVE-2026-33825. This issue, known as BlueHammer, allows an authenticated attacker to elevate local privileges by exploiting overly broad access control, which can lead to SYSTEM-level control and full compromise. CISA added CVE-2026-33825 to its KEV catalog and urged rapid patching because it is now tied to real ransomware activity.
Reported exploitedMicrosoft Defender - SecurityWeekCritical SimpleHelp Vulnerability Exploited for Malware Delivery
A critical authentication bypass in SimpleHelp remote monitoring and management (RMM) software has been used to deliver malware, tracked as CVE-2026-48558 (CVSS 10). The flaw impacts SimpleHelp’s OpenID Connect (OIDC) login flow by letting attackers supply forged identity tokens to obtain fully authenticated technician sessions, enabling remote file transfer and command execution over systems managed by the server. Observed intrusions deployed TaskWeaver and Djinn Stealer, while SimpleHelp addressed the issue in versions 5.5.16 and 6.0 RC2; CISA also added CVE-2026-48558 to its KEV catalog to prompt rapid patching.
Reported exploitedSimpleHelp - The Hacker NewsProgress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
Progress Kemp LoadMaster discloses a critical pre-auth remote command execution issue in its API that can allow an unauthenticated attacker to run arbitrary commands as root by sending a crafted request. The vulnerability is tracked as CVE-2026-8037 (CVSS 9.8) and affects LoadMaster GA v7.2.63.1 and older, plus LTSF v7.2.54.17 and older when the API is enabled; fixed releases are GA v7.2.63.2 and LTSF v7.2.54.18. The bug matters because the affected /accessv2 endpoint is reachable before authentication, and a public proof of concept has been demonstrated even though no exploitation reports have been made.
PoC publicKemp LoadMaster - The Hacker NewsApple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Apple released security updates for iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 to address 30+ vulnerabilities, including multiple WebKit flaws identified with AI tooling such as Anthropic Claude and OpenAI Codex Security. The WebKit issues include CVE-2026-43707, CVE-2026-43716, CVE-2026-43745, and CVE-2026-43715, which range from memory corruption to out-of-bounds writes and can crash Safari or enable broader memory-safety impact. Apple also patched additional issues affecting the kernel, including CVE-2026-43722, CVE-2026-43724, and CVE-2026-39868—making these updates important for reducing risk even though none are reported as exploited in the wild.
PatchiOS - The Hacker NewsOracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Oracle E-Business Suite’s Oracle Payments component is facing a critical actively exploited weakness, tracked as CVE-2026-46817 (CVSS 9.8). The issue involves improper privilege management and authentication that can be abused by a network-based unauthenticated attacker over HTTP to take over affected Oracle Payments instances (versions 12.2.3 through 12.2.15). This matters because it indicates real-world compromise attempts are underway, and organizations should verify they have applied Oracle’s latest security patches.
Reported exploitedOracle E-Business Suite
Monday, Jun 2915 stories
- Dark Reading
- Dark Reading'Djinn' Stealer Targets Cloud, AI Credentials
A campaign targeting the remote management product SimpleHelp has been observed using the critical authentication bypass vulnerability CVE-2026-48558 as an entry point. After exploiting an Internet-facing SimpleHelp instance, attackers gained technician-level access, deployed a JavaScript loader (TaskWeaver), and delivered Djinn Stealer to collect and encrypt high-value secrets. The malware can harvest cloud and developer credentials—including keys and configuration data tied to AI tooling/agents—highlighting why RMM compromise can quickly escalate into broader access and downstream supply-chain risk.
Reported exploitedSimpleHelp - BleepingComputerNissan discloses employee data breach linked to Oracle zero-day attacks
Nissan says attackers exploited an Oracle PeopleSoft vulnerability to steal employee information, and the incident may have affected current and former staff. The breach has been connected to exploitation of Oracle PeopleTools zero-day CVE-2026-35273, a flaw that was used in data-theft operations previously attributed to the ShinyHunters extortion group. This matters because exposed payroll and identity data can enable further fraud and long-term account and tax-related abuse.
Reported exploitedOracle PeopleSoft - BleepingComputerNAIC says public data stolen in ShinyHunters' PeopleSoft breach
The NAIC says it was compromised by ShinyHunters after the threat group exploited a zero-day in an Oracle PeopleSoft server (CVE-2026-35273). According to NAIC, the attackers obtained mainly already publicly available statutory financial reports, outdated logs, and configuration information, and it reports no evidence that PII or financial data was exposed. The incident still caused disruptions for downstream partners, while ShinyHunters’ leaked-file claims differ from NAIC’s findings and NAIC states affected systems have been remediated.
Reported exploitedOracle PeopleSoft - watchTowr Labs
- Help Net SecurityJSP webshells being dropped on unpatched PTC Windchill instances
CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog, warning that PTC Windchill and FlexPLM are being targeted in the wild. PTC reports that attackers can exploit the improper input validation flaw (unauthenticated remote code execution) and has observed indicators consistent with JSP webshells being deployed on vulnerable systems. Organizations using affected PTC product lifecycle management deployments should apply the relevant patches and check their environments for indicators of compromise.
Reported exploitedWindchill - The Hacker News⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
Researchers disclosed DirtyClone (CVE-2026-43503), a new variant of the Dirty Frag Linux kernel issue that can let local users achieve root by abusing cloned packets. JFrog notes the risk is especially high on multi-tenant cloud setups, Kubernetes clusters, and containers when user namespaces are enabled and attackers can obtain CAPNETADMIN. The wider roundup also highlights active exploitation of CVE-2026-12569 in PTC Windchill PDMlink and PTC FlexPLM, underscoring how missed patches and old access paths continue to drive real-world compromise.
- Check Point Research29th June – Threat Intelligence Report
In Check Point Research’s 29th June threat intelligence update, multiple incidents were highlighted, including a supply-chain compromise impacting Polymarket customers, a reported KDDI ISP email platform breach affecting up to 14.22 million email addresses and passwords, and a Tata Electronics data breach involving alleged 630GB of leaked material. On the vulnerabilities front, Cisco fixed actively exploited CVE-2026-20245 in Catalyst SD-WAN Manager, Dify released 1.14.2 to address critical issues including CVE-2026-41947 and CVE-2026-41948, and Ubiquiti UniFi OS was flagged for exploitation of CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. The report also notes ongoing targeting of Langflow via CVE-2026-55255 and mass exploitation of CVE-2026-33017, underscoring how quickly attackers weaponize new weaknesses.
- BleepingComputerCritical SimpleHelp flaw exploited to deploy new stealer malware
Attackers are actively exploiting a recently disclosed critical vulnerability in SimpleHelp (CVE-2026-48558) to compromise exposed instances and deploy new malware, including Djinn Stealer and a TaskWeaver loader. The affected SimpleHelp deployments—often used by MSPs, IT teams, and helpdesks—matter because the flaw can be used to bypass authentication via OpenID Connect (OIDC), enabling attackers to gain a trusted technician session for remote execution. Djinn Stealer then targets cross-platform developer and infrastructure data on Windows, macOS, and Linux, potentially allowing theft of credentials and downstream access to cloud resources, repositories, and API-connected AI tooling.
Reported exploitedSimpleHelp - BleepingComputerHackers now exploit critical Oracle E-Business flaw in attacks
Threat actors are actively exploiting a critical issue in Oracle E-Business Suite (EBS) that tracks as CVE-2026-46817. The weakness affects the File Transmission component within Oracle Payments and allows unauthenticated attackers with HTTP network access to take over vulnerable systems. Oracle has released fixes in its May 2026 Critical Security Patch Update, and the public exploitation increase makes prompt patching especially important for exposed EBS instances.
Reported exploitedOracle E-Business Suite - SecurityWeekInsurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
The National Association of Insurance Commissioners (NAIC) says it was targeted in the recent Oracle PeopleSoft attack chain involving the zero-day vulnerability CVE-2026-35273, which enables unauthenticated remote code execution. NAIC reports unauthorized access discovered on June 11, with attackers obtaining statutory financial reporting and related technical data; however, it states personally identifiable information and payment/financial account details were not compromised. The incident matters because a widely used enterprise platform vulnerability is being actively leveraged by the ShinyHunters group and regulators are now confirming real-world impact.
Reported exploitedOracle PeopleSoft - Dark ReadingAmazon Q VS Extension Flaw Leads to Cloud Credential TheftPatchAmazon Q Developer extension
- The Hacker NewsGamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
The Russian APT group Gamaredon has intensified its cyber campaign against Ukraine throughout 2025 by expanding its malware and increasing the use of legitimate third-party online services for command-and-control, exfiltration, and “dead drop” infrastructure. ESET reports 35 spear-phishing campaigns targeting Ukrainian government and military organizations, including attacks that abused a patched WinRAR flaw tracked as CVE-2025-8088 to deliver an HTA downloader and establish persistence. This matters because the continued weaponization of archive-based delivery and cloud/service impersonation makes detection and disruption significantly harder across affected environments.
Reported exploitedGamaredon - SecurityWeek‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access
JFrog disclosed details and a PoC for CVE-2026-43503, a high-severity Linux kernel local privilege escalation vulnerability that can let any local user obtain root access (CVSS 8.8). The issue is a variant related to the DirtyFrag (Copy Fail 2) and Fragnesia vulnerability family, and it stems from memory corruption in the kernel’s networking skb processing and zero-copy page-cache interactions. Debian, Fedora, and Ubuntu are potentially impacted when unprivileged user namespaces are enabled, and attackers with CAPNETADMIN on an affected kernel can escalate to root—posing particular risk for multi-tenant cloud, Kubernetes, and container environments.
PoC publicLinux kernel - The Hacker NewsPublic PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept has been released for CVE-2026-55200, a critical memory corruption issue in libssh2 (affecting all releases up to and including 1.11.1) that allows a malicious or compromised SSH server to trigger heap overflow during the SSH handshake, potentially leading to code execution without credentials or user interaction. Because libssh2 is commonly embedded in products like curl, Git, PHP, and various embedded/firmware updaters—often as statically linked binaries—many systems may remain vulnerable even if package updates aren’t straightforward. Mitigation depends on applying the upstream fix (commit 97acf3dfda80c91c3a8c9f2372546301d4a1a7a8) or waiting for downstream patched releases, while restricting outbound SSH access to trusted endpoints until then.
PoC publiclibssh2
Sunday, Jun 281 story
- Help Net SecurityWeek in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedReported exploitedFortiGate firewall
Friday, Jun 2610 stories
- BleepingComputerCISA sets urgent deadline to fix Cisco flaw exploited in attacks
CISA has issued an urgent directive for federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server, a server-side request forgery (SSRF) issue that is already being exploited in the wild and is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog. Cisco rated it critical and released a fix on June 3, warning it can be triggered remotely without authentication through specially crafted HTTP requests, and researchers have reported observed attacks leveraging it to write arbitrary text files. The deadline to remediate is Sunday, June 28, and CISA also added CVE-2026-12569 to KEV for PTC Windchill and FlexPLM (improper input validation leading to remote code execution).
AdvisoryPTC Windchill - Rapid7 BlogWeekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more
Rapid7’s Metasploit Framework update introduces new scanners and an exploit module, including a Next.js Middleware Authorization Bypass scanner for CVE-2025-29927, a LiteLLM proxy pre-auth SQL injection scanner for CVE-2026-42208, and an unauthenticated Audiobookshelf API authentication bypass scanner for CVE-2025-25205 (fixed in 2.19.1 for affected releases 2.17.0–2.19.0). The release also adds a Dalfox found-action deserialization RCE exploit for Dalfox Server versions <= 2.12.0 tied to CVE-2026-45087. These additions matter because they help detect and potentially validate high-impact pre-auth and authorization flaws, as well as remote code execution via unsafe deserialization paths.
ResearchAudiobookshelf - The Hacker NewsNew SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly identified campaign dubbed StrikeShark distributes the previously unknown Windows malware family SharkLoader, which then deploys Cobalt Strike Beacon on compromised systems. Kaspersky reports targeting includes organizations in Indonesia, Taiwan, and multiple other countries, using publicly available post-compromise tools and opportunistic exploitation of exposed services. The initial access leverages vulnerabilities such as ProxyLogon (CVE-2021-26855), Openfire traversal flaws (CVE-2023-32315), and GeoServer remote code execution (CVE-2024-36401), highlighting an elevated risk of espionage and follow-on payload delivery.
PoC publicMicrosoft SharePoint - SecurityWeekAmazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
Wiz reported a high-severity issue in the Amazon Q Developer extension for Visual Studio Code where opening a booby-trapped repository could trigger automatic actions on workspace configuration files without user consent. This could allow attackers to run attacker-controlled commands and inherit the developer’s environment, potentially capturing AWS or other cloud credentials and API keys—tracked as CVE-2026-12957, with a related symbolic link issue CVE-2026-12958. AWS issued patches (including fixes in the Amazon Q Developer language server, noted as version 1.65.0) and says updates are available for affected plugins covering VS Code, JetBrains, Eclipse, and Visual Studio.
PatchAmazon Q Developer - The Hacker NewsNew Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
A Linux kernel vulnerability in the traffic-control packet-editing action (actpedit), tracked as CVE-2026-46331 (“pedit COW”), can allow an unprivileged local user to gain root. The issue is an out-of-bounds write that corrupts shared page-cache content, enabling an attacker to poison the in-memory copy of /bin/su without touching the disk, bypassing file integrity checks after exploitation. Public working exploits appeared shortly after the CVE was assigned, and Red Hat, Debian, and Ubuntu kernels are affected (per their advisories), making timely patching and mitigation important for multi-tenant and containerized environments.
PoC publicLinux Kernel - The Hacker NewsAmazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
A high-severity issue in Amazon Q Developer could allow a malicious repository to trigger command execution and potentially steal developers’ cloud credentials through Model Context Protocol (MCP) server settings. The vulnerability is tracked as CVE-2026-12957 (CVSS 8.5) and affects the Language Servers for AWS component used by Amazon Q across VS Code, JetBrains, Eclipse, and Visual Studio, where repo-bundled MCP configuration could lead to running attacker-defined servers in the developer’s environment. This matters because it can turn trusted code checkout into unauthorized access to AWS identity and sensitive credentials unless systems are updated with the vendor’s fix.
PatchAmazon Q Developer - Kaspersky SecurelistCVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systemsResearchFloating License Manager
- The Hacker NewsCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
CISA has added a actively exploited remote code execution flaw to its Known Exploited Vulnerabilities (KEV) catalog, affecting PTC Windchill PDMlink and PTC FlexPLM. The issue is tracked as CVE-2026-12569 (CVSS 9.3), where improper input validation can enable arbitrary code execution. PTC reports that attackers are continuing to use the vulnerability to install JSP web shells on vulnerable systems, underscoring the risk of rapid weaponization after patch releases.
Reported exploitedPTC Windchill - Daily CyberSecurity (securityonline.info)Cisco SD-WAN Zero-Day Exploited in Attacks
An unnamed threat actor exploited a Cisco SD-WAN zero-day against service provider infrastructure, with Mandiant reporting evidence of compromise. The attackers targeted Cisco Catalyst SD-WAN Manager and used a malicious CSV upload path to trigger CVE-2026-20245, ultimately escalating to root-level control and conducting anti-forensic actions. Organizations running affected Cisco SD-WAN components should upgrade to the fixed releases listed by the vendor to eliminate CVE-2026-20245 risk and reduce further intrusion likelihood.
Reported exploitedCisco Catalyst SD-WAN Manager - The Hacker NewsNew DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets
A newly disclosed Linux kernel flaw in the DirtyFrag family, called DirtyClone, can allow a local attacker to corrupt file-backed memory via cloned packet handling and achieve root privileges. The issue is tracked as CVE-2026-43503 (CVSS 8.8) and matters because the demonstrated technique modifies in-memory data only—so file integrity tools may not detect it and a reboot restores the original binary. JFrog Security Research has shared a working exploit, and the fix has already landed upstream; unpatched systems should update their kernels promptly.
PoC publicLinux Kernel