Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Wednesday, Jun 248 stories
- Daily CyberSecurity (securityonline.info)SmartRAT ClickFix Campaign IdentifiedResearchSmartRAT
- The Hacker NewsCisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to RootReported exploitedCisco Unified CM
- SecurityWeekHackers Exploiting Cisco Unified CM Vulnerability
Security researchers report that CVE-2026-20230 in Cisco Unified Communications Manager (Unified CM) is being exploited in the wild shortly after Cisco released patches on June 3. The unauthenticated, remote issue can be leveraged for SSRF, arbitrary file writes to the underlying OS, and privilege escalation to root (with exploitation tied to enabling the WebDialer service, which is disabled by default). This matters because Unified CM is a widely deployed on-premises call control platform, making the flaw attractive for both criminal and state-sponsored actors.
Reported exploitedCisco Unified CM - Daily CyberSecurity (securityonline.info)Public Details Disclosed: MediaTek t7xx WWAN FlawAdvisoryMediaTek t7xx WWAN
- Daily CyberSecurity (securityonline.info)AVer PTC Cameras Hit by Critical RCE Flaw CVE-2026-40624 (CVSS 9.8)PatchAVer PTC500S
- Daily CyberSecurity (securityonline.info)Containerd Critical Vulnerabilities Expose Host ServersPatchcontainerd
- Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)
Tuesday, Jun 2317 stories
- Daily CyberSecurity (securityonline.info)CISA Adds Four Exploited UniFi OS and Lantronix Flaws to KEV CatalogReported exploitedUbiquiti UniFi OS
- BleepingComputerCisco Unified CM flaw CVE-2026-20230 now exploited in attacksReported exploitedCisco Unified CM
- SecurityWeekData Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
SecurityWeek reports that four security issues in the open source AI platform Dify can be abused in multi-tenant cloud setups to access or exfiltrate data belonging to other customers. The affected vulnerabilities are tracked as CVE-2026-41947, CVE-2026-41948, CVE-2026-41949, and CVE-2026-41950, and they impact components such as Dify tracing, the plugin daemon, and file handling/permissions, enabling actions like reading other tenants’ chats, previewing documents, and invoking cross-tenant APIs. Zafran further notes the preview endpoint relied on a vulnerable Chromium PDFium binary (126.0.6462.0) tied to CVE-2024-5846, and Dify version 1.14.2 is released with patches to address these findings—users should upgrade promptly and consider WAF mitigations for CVE-2026-41948.
ResearchDify - BleepingComputerThe Exploit Doesn't Exist. You Can Still Prove It Works Against You
A recent report highlights that exploit development is increasingly happening in hours rather than months, putting pressure on traditional remediation timelines and leaving gaps between patching and active attack development. It calls out the risk that even when exploitation details aren’t publicly available or can’t be safely tested, teams still need evidence-based exposure decisions—for example, Windows CLFS issue CVE-2025-29824 (CLFS use-after-free leading to SYSTEM). The takeaway: faster pentests aren’t enough when live firing isn’t possible, so organizations should validate the required attacker TTP chain against their actual controls instead of relying solely on CVSS/EPSS-style scoring.
Research - SecurityWeekEight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks
Researchers uncovered a long-standing high-severity vulnerability in Samsung’s KNOX kernel affecting nearly all Galaxy devices from Galaxy S9 through S25. The issue, tracked as CVE-2026-20971, can be triggered via interactions between PROCA and FIVE and may result in kernel memory corruption through a race-condition use-after-free scenario, even though exploitation is described as requiring local conditions and user interaction. Samsung addressed the problem in its January 2026 update for affected Android releases including Android 13, 14, 15, and 16, and device coverage spans both Exynos- and Qualcomm-based models; timely patching matters because mobile attacks can be leveraged for deeper compromise.
ResearchGalaxy S9 - SecurityWeekFFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
A heap out-of-bounds write in FFmpeg’s libavcodec MagicYUV decoder, tracked as CVE-2026-8461 (CVSS 8.8), can allow attackers to crash applications and potentially execute arbitrary code using specially crafted video files. JFrog describes the PixelSmash flaw as stemming from a mismatch in how the frame allocator and decoder calculate chroma plane heights, and notes that exploitation can be tailored to target FFmpeg’s AVBuffer refcounted buffer handling. Fixed in FFmpeg version 8.1.2, the issue affects a wide range of media players and servers that decode videos with FFmpeg, including Kodi, mpv, ffmpegthumbnailer, Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio—so updating promptly matters.
PatchFFmpeg - Daily CyberSecurity (securityonline.info)Dropping Elephant Malware: China-Themed Loader Campaign AnalyzedResearchDropping Elephant
- Daily CyberSecurity (securityonline.info)AryStinger Malware Attacks Routers via CVE-2013-3307ResearchRTL819X routers
- Daily CyberSecurity (securityonline.info)
- The Hacker NewsOpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
OpenAI says it is expanding its Daybreak initiative by releasing an improved trusted version of GPT-5.5-Cyber for defenders to help analyze large codebases, validate security issues, and generate/test patches. It is also updating the Codex Security plugin to accelerate vulnerability discovery and patch workflows, including triaging findings from scanners and advisories. The article highlights that Daybreak efforts have been associated with vulnerabilities such as CVE-2026-47729 (Squidbleed) and CVE-2026-8390 (WebAssembly in Mozilla Firefox), underscoring why faster remediation matters as frontier AI can also shorten the time between disclosure and exploitation.
Research - SANS Internet Storm CenterCVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.
SonicWall addressed the improper access control flaw CVE-2024-40766 in SonicOS, impacting the management interface and SSLVPN service on Gen 5, Gen 6 and Gen 7 firewalls; however, threat actors (including Akira and Fog) have continued exploiting patched devices by abusing leftover configuration and credential issues rather than “new” bypasses. Active intrusions have also highlighted additional risk on Gen 6 related to CVE-2024-12802, where firmware-only patching may not remove the MFA bypass condition. The takeaway: organizations must not only apply SonicOS updates, but also complete post-patch cleanup (rotate passwords, remove stale/orphaned users, correct LDAP group settings, and restrict the Virtual Office Portal) to close the exploitable gaps.
Reported exploitedSonicOS - Daily CyberSecurity (securityonline.info)Tinyproxy Request Smuggling Flaws Expose NetworksPatchTinyproxy
- Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)MariaDB Server Vulnerabilities Allow CVSS 10 AttacksPatchMariaDB server
- Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Vendor-Signed UEFI Applications Allow Secure Boot BypassPatchUEFI applications
- Daily CyberSecurity (securityonline.info)
Monday, Jun 2215 stories
- Dark ReadingDifyTap Bugs Let Attackers 'Wiretap' AI Chat HistoriesResearchDify AI Platform
- BleepingComputerFFmpeg fixes PixelSmash flaw in widely used video decoder
FFmpeg has patched a newly reported “PixelSmash” issue (CVE-2026-8461), a heap out-of-bounds write in the MagicYUV decoder that can be triggered by specially crafted video files in AVI, MKV, or MOV formats. The flaw matters because it may lead to remote code execution on affected FFmpeg-based products under specific conditions (e.g., when ASLR is disabled or combined with other weaknesses), and it can also cause denial-of-service crashes; reported targets include Jellyfin and media software such as Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. The fix is included in FFmpeg version 8.1.2, and anyone using libavcodec with MagicYUV support should update and assess exposure.
PatchMagicYUV decoder - The Hacker NewsShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
ShapedPlugin says multiple WordPress Pro plugins were backdoored in a supply chain incident after attackers tampered with its official release and licensed update distribution. The affected plugins are Product Slider Pro for WooCommerce (versions before 3.5.4), Real Testimonials Pro (version 3.2.5), and Smart Post Show Pro (versions before 4.0.2), delivered through ShapedPlugin’s Easy Digital Downloads (EDD) infrastructure at account.shapedplugin[.]com—while free versions on WordPress.org were not impacted. Security researchers link the incident to CVE-2026-10735 (CVSS 9.8) and CVE-2026-49777 (CVSS 10.0), highlighting the risk to legitimate license holders via trusted vendor updates and the potential for credential theft and persistence.
Reported exploitedProduct Slider Pro for WooCommerce - The Hacker NewsResearchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across TenantsResearchDify platform
- Check Point Research22nd June – Threat Intelligence Report
This week’s Check Point Research roundup highlights multiple incidents and vulnerabilities affecting several vendors. A supply-chain attack targeting ShapedPlugin WordPress plugins delivered a hidden malicious WooCommerce component to steal admin, database, and 2FA credentials, while Fortinet FortiSandbox flaws CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 are reported as being exploited via unauthenticated API requests. Other actively targeted issues include Microsoft Defender CVE-2026-50656, Cisco Catalyst SD-WAN Manager CVE-2026-20262, and Splunk Enterprise CVE-2026-20253, where exploitation can enable privilege escalation or remote code execution—making patching and exposure review urgent.
RoundupFortinet FortiSandbox - The Hacker News29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
A heap over-read in the Squid web proxy can expose another user’s cleartext HTTP request, potentially including credentials or session tokens, to attackers who already have permission to use the same proxy. The issue, called Squidbleed, is tracked as CVE-2026-47729 and is reported to affect Squid’s default configuration, with the attack requiring access patterns tied to Squid’s FTP parsing (including an FTP server on port 21). This matters because it can break confidentiality in shared proxy environments such as offices, schools, and public Wi‑Fi; however, HTTPS traffic behind CONNECT remains opaque to Squid.
PoC publicSquid web proxy - SecurityWeekDecades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
Calif.io researchers reported a long-standing memory leak issue in Squid Proxy, tracked as CVE-2026-47729, affecting the FTP handling logic dating back to 1997. By manipulating an attacker-controlled FTP server, the proxy can read past a memory buffer and potentially disclose remnants of prior users’ uncleared HTTP requests, which is especially concerning in shared proxy deployments (e.g., corporate networks, schools, and public Wi‑Fi). While the impact is mainly limited to cleartext HTTP scenarios where Squid terminates TLS, sensitive credentials and session data may still be exposed without detection.
ResearchSquid Proxy - The Hacker NewsStop Your Legacy Infrastructure from Hijacking Your AI Agents
A recent analysis from XM Cyber warns that attackers can bypass AI security controls by pivoting through outdated or misconfigured systems that the AI agent depends on. It highlights an example chain involving Apache Tomcat with CVE-2025-24813, where lack of patching can lead to credential theft, Active Directory compromise, and then access to S3 data used by the AI agent’s knowledge base. This matters because CVE-driven weaknesses in “legacy” network and identity layers can translate into full compromise of AI agent outputs without directly attacking the AI stack itself.
ResearchAWS Bedrock - SecurityWeekAttackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Attackers are actively exploiting a medium-severity information exposure weakness in the Gravity SMTP WordPress plugin (all versions before 2.1.5) tracked as CVE-2026-4020 (CVSS 5.3). The flaw allows unauthenticated access to a REST API endpoint that can return the full “System Report” JSON, including server and WordPress configuration details as well as stored connector data like API keys/tokens used for email integrations. This matters because leaked credentials could enable attackers to send emails through the compromised site and use the detailed reconnaissance to pursue further vulnerabilities; Defiant reports exploitation in the wild since early May and a surge in attempts during June.
Reported exploitedGravity SMTP for WordPress - The Hacker News⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreRoundupFortinet FortiGate
- SecurityWeekFortinet Responds to FortiBleed Campaign
Fortinet has responded to the ongoing FortiBleed campaign, which is reportedly targeting its customers’ firewalls and VPNs with large-scale credential harvesting rather than exploiting a new product vulnerability. The activity centers on reusing previously obtained credentials and brute-force attempts against devices with weak password practices and missing multi-factor authentication, affecting Fortinet deployments across many regions. The vendor says earlier FortiCloud SSO login bypass issues—CVE-2026-24858 and CVE-2025-59718/CVE-2025-59719—are the related defects that were patched, underscoring why users must complete the recommended remediations and harden admin/VPN access.
Reported exploitedFortiGate - Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Apache Doris SQL Injection Vulnerability CVE-2025-66336PatchApache Doris MCP Server
- Daily CyberSecurity (securityonline.info)Microsoft Edge Google Account Login Coming SoonAdvisoryMicrosoft Edge
- The Hacker NewsAryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
QiAnXin’s XLab reports that its AryStinger malware has infected at least 4,300 legacy routers and repurposes them for pre-intrusion reconnaissance and proxying (scanning, service fingerprinting, subdomain enumeration, tunneling, and on-demand command execution). The activity targets routers using Realtek RTL819X chips and exploits older, already-public issues: CVE-2013-3307 (Linksys) and CVE-2016-5681 (D-Link), with the majority of infected devices attributed to D-Link models such as DIR-850L. A separate strain was also observed against QNAP systems via CVE-2025-11837 in QNAP's Malware Remover, underscoring how unsupported networking gear can be used to build resilient attacker infrastructure.
Reported exploitedLinksys routers (RTL819X-based models)