Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Monday, Jun 227 stories
- Daily CyberSecurity (securityonline.info)DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN RelaysReported exploitedMicrosoft Teams
- Daily CyberSecurity (securityonline.info)2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)Reported exploitedSplunk Enterprise
- Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress SitesReported exploitedWordPress sites
- Daily CyberSecurity (securityonline.info)Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails AppsPoC publicAvo admin panel framework
- Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Public Exploit Released for FreeBSD kTLS Local Root Flaw CVE-2026-45257PoC publicFreeBSD kTLS
Sunday, Jun 212 stories
- BleepingComputerAryStinger botnet infected thousands of D-Link routers worldwide
Researchers report the AryStinger malware botnet has infected more than 4,000 outdated D-Link routers, turning them into remotely controlled “executors” used for scanning, proxying, tunneling, and command execution. The botnet targets devices with multiple known weaknesses, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, with primary impact on D-Link DIR-850L and D-Link DIR-818LW. This matters because compromised routers can also tamper with DNS settings, hijack browsing, and monitor traffic for potential data theft or further intrusions.
ResearchAryStinger - Daily CyberSecurity (securityonline.info)QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices
QNAP has released patches addressing 14 vulnerabilities affecting QTS, QuTS hero, QuTS cloud, and QVP devices, with issues including command injection, credential theft, and denial-of-service conditions. Reported CVE IDs include CVE-2025-66273, CVE-2025-66279, CVE-2026-22893, and CVE-2025-59382, which together enable attackers to execute commands, tamper with password reset flows, or crash services. Because NAS appliances are high-value targets reachable from the network edge, applying the fixed firmware updates (e.g., QTS 5.2.10, QuTS hero h5.2.9, QuTS cloud C5.2.9, QVP 2.8.0) is important even though no active exploitation has been confirmed.
PatchQTS
Saturday, Jun 201 story
- The Hacker NewsHackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Threat actors are actively exploiting a patched vulnerability in the WordPress plugin Gravity SMTP (installed on roughly 100,000 sites) to expose sensitive information. The issue, tracked as CVE-2026-4020 (CVSS 5.3), is an unauthenticated information disclosure flaw that can leak configuration details, secrets, and third-party email integration API keys/tokens via a REST endpoint. This matters because exposed credentials can be reused to send email through connected services, and attackers can also gather detailed system information to support follow-on attacks; the vendor fix is available in Gravity SMTP version 2.1.5.
Reported exploitedGravity SMTP
Friday, Jun 1916 stories
- BleepingComputerHackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, impacting deployments on an estimated 100,000 sites. The issue is tracked as CVE-2026-4020 and affects all versions from 2.1.4 and earlier; it was addressed in version 2.1.5 (released March 17). By accessing an exposed REST API endpoint, attackers can retrieve a detailed JSON “System Report” that may include API keys, email service credentials for providers like Amazon SES, Google, Mailjet, Resend, and Zoho, and environment/configuration details—enabling account and credential abuse and helping plan further attacks.
Reported exploitedGravity SMTP - Rapid7 BlogWeekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and morePoC publicMetasploit Framework
- The Hacker NewsAutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Microsoft researchers describe the AutoJack exploit chain, which can let a single web page hijack an AI browsing agent into remote code execution on the host by targeting the MCP WebSocket handler in AutoGen Studio. Reported impact centers on pre-release versions 0.4.3.dev1 and 0.4.3.dev2 (while the standard PyPI install of 0.4.2.2 is stated to be unaffected) and is fixed in GitHub main at commit b047730. The broader risk pattern is tied to previous findings in Microsoft ecosystems, including CVE-2026-26030 and CVE-2026-25592, underscoring that “localhost” trust boundaries can fail when agents can both browse untrusted content and reach privileged local services.
PoC publicAutoGen Studio - SecurityWeek
- BleepingComputerCISA: Splunk Enterprise flaw actively exploited, patch by SundayReported exploitedSplunk Enterprise
- Daily CyberSecurity (securityonline.info)Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem
IBM X-Force published a two-year investigation into the Interlock and Rhysida ransomware ecosystem, highlighting how the two operations share multiple enabling components such as loaders, crypters, and backdoors. Interlock (tracked as Hive0163) and Rhysida (operating as RaaS since at least May 2023) reportedly show overlapping infrastructure ties, including the Supper backdoor (SocksShell or WINDYTWIST) and code similarities across families like NodeSnake, InterlockRAT, and JunkFiction. The analysis also notes exploitation of CVE-2026-20131 and CVE-2023-36036 for initial compromise and privilege escalation, underscoring why defenders should monitor the entire kill chain—not just the final ransomware payload.
ResearchInterlock ransomware - Daily CyberSecurity (securityonline.info)1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)
A critical vulnerability in themefusion Avada (Fusion) Builder, tracked as CVE-2026-8713 (CVSS 9.1), allows unauthenticated attackers to delete arbitrary files on affected servers without login. Versions at or below 3.15.3 are impacted, and the ability to remove sensitive files can lead to full compromise of a WordPress site. Site owners should upgrade to Avada Builder v3.15.4 or later immediately, even though there is no confirmed public exploitation reported yet.
PatchAvada Builder (Fusion) - The Hacker NewsApple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via MicrophonePoC publicBeats Studio Buds
- Daily CyberSecurity (securityonline.info)Chrome Extension Vulnerabilities: Millions at Risk
Rebora Security Research reports critical Chrome extension vulnerabilities affecting SiderAI and MaxAI, with issues tracked as CVE-WATCHTOWER. The defects, named Spyder and MaXSS, let attackers abuse extension content scripts to trigger actions without user interaction, including stealing sensitive data and issuing unauthorized commands. Because these extensions are installed on more than 10,000,000 and 1,000,000+ devices respectively, the flaws significantly increase the risk of large-scale browser compromise.
ResearchSiderAI - SecurityWeekSplunk Enterprise Vulnerability Exploited in Attacks Days After DisclosureReported exploitedSplunk Enterprise
- Daily CyberSecurity (securityonline.info)F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)
F5 issued urgent out-of-band fixes for two high-impact NGINX vulnerabilities, CVE-2026-42530 (HTTP/3 use-after-free) and CVE-2026-42055 (conditional HTTP/2 heap-based buffer overflow). Both can be triggered by a remote, unauthenticated attacker and carry a CVSS v4.0 score of 9.2, with issues affecting NGINX worker process stability and potential security impact depending on system hardening. This matters because the flaws target widely deployed HTTP/2/HTTP/3 and specific NGINX module paths, so even limited configuration exposure can still affect a large number of deployments.
PatchNGINX Open Source - Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)27-Year-Old OpenBSD Authentication Bypass: Details and PoC Exploit Publicly DisclosedPoC publicOpenBSD PPP stack
- Daily CyberSecurity (securityonline.info)LiteLLM Authentication Bypass via Host Header Injection (CVE-2026-49468)
LiteLLM’s authentication can be bypassed when a malicious actor injects a crafted HTTP Host header, potentially allowing unauthenticated access to protected management routes. The issue is tracked as CVE-2026-49468 (CVSS 9.5) affecting litellm (pip) versions earlier than < 1.84.0, making it critical for deployments that expose the proxy directly. Update to 1.84.0 to remediate; no confirmed exploitation was reported at the time of disclosure.
PatchLiteLLM AI Gateway - Daily CyberSecurity (securityonline.info)Langflow File Upload Flaw: Details and PoC Exploit Publicly Disclosed (CVE-2026-55450)PoC publiclangflow (pip)
- Daily CyberSecurity (securityonline.info)Rockwell Automation patches multiple ICS flawsPatchFactoryTalk Historian Site Edition
Thursday, Jun 1814 stories
- Ars Technica (Security)Apple patches high-severity eavesdropping vulnerability in Beats Studio BudsPatchBeats Studio Buds
- Dark ReadingOperation Escaneo Signals Shift in LatAm Threat LandscapeResearchMexicanMafia
- Daily CyberSecurity (securityonline.info)Splunk CVE-2026-20253: CVSS 9.8 RCE Exploited in the Wild
CISA has added Splunk [CVE-2026-20253] to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw affects Splunk Enterprise versions 10.2 (below 10.2.4) and 10.0 (below 10.0.7), where an authentication weakness in the PostgreSQL sidecar service can enable pre-authenticated remote code execution. Organizations should upgrade to 10.2.4 or 10.0.7 immediately (or disable the PostgreSQL sidecar service as a temporary mitigation) to reduce the risk of compromise.
Reported exploitedSplunk Enterprise - Daily CyberSecurity (securityonline.info)Node.js Security Updates: Urgent Action Required
The Node.js project has issued critical and high-severity security updates that affect the 26.x, 24.x, and 22.x release lines, with patched versions listed as Node.js v22.23.1, v24.17.1, and v26.3.2. Among the fixed issues are CVE-2026-48933 (a WebCrypto AES integer overflow that can crash the process via subtle.encrypt()), and CVE-2026-48618 (a TLS authentication bypass tied to unicode dot separator handling). Additional vulnerabilities include CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48617, CVE-2026-48935, CVE-2026-48936, and CVE-2026-48931, so organizations should upgrade promptly to reduce exposure to DoS and authentication/validation bypasses.
PatchNode.js - The Hacker NewsF5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
F5 has released patches for two high-severity vulnerabilities affecting NGINX Open Source that could be exploited by unauthenticated remote attackers to achieve remote code execution (RCE): CVE-2026-42530 and CVE-2026-42055. The issues involve a use-after-free in ngxhttpv3module when HTTP/3 QUIC is used, and a heap-based buffer overflow in ngxhttpproxyv2module/ngxhttpgrpcmodule when proxying HTTP/2 with specific settings, potentially impacting systems even with ASLR depending on attacker conditions. Users should update to the fixed versions listed by F5 (notably NGINX Open Source 1.31.2 for CVE-2026-42530 and 1.31.2 / 1.30.3 paths for CVE-2026-42055) and consider F5’s mitigations such as disabling HTTP/3 or removing/reducing the configuration options that enable the second flaw.
ResearchESET - The Hacker News
- Qualys Security BlogOracle Critical Patch Update, June 2026 Security Update ReviewPatchOracle Fusion Middleware
- The Hacker NewsINC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023Reported exploitedAcronis
- The Hacker NewsDragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 TrafficReported exploitedBackdoor.Turn
- BleepingComputerShapedPlugin update flow hacked to infect WordPress sites
ShapedPlugin says multiple of its WordPress plugins were compromised in a supply-chain attack that inserted malicious code into legitimate releases delivered through the vendor’s official update mechanism. The affected paid plugins are Product Slider Pro before 3.5.4 for WooCommerce, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2, where attackers used backdoored builds to steal credentials and enable remote file-writing via impersonated WooCommerce components. WordPress tracking for this incident includes CVE-2026-10735 (with CVE-2026-49777 submitted as a duplicate), highlighting why updating from trusted channels can still be risky when build pipelines are compromised.
Reported exploitedProduct Slider Pro - BleepingComputerApple fixes Beats Studio Buds flaw that let hackers spy on conversations
Apple has released security updates for Beats Studio Buds to address a high-severity Bluetooth vulnerability that could let attackers within radio range listen via the earbuds’ microphone when the device is unpaired and seeking pair requests. The issue is tracked as CVE-2025-20701 and was fixed in Beats Firmware Update 1B211; in many cases the update is applied automatically when the earbuds pair within range of an iPhone, iPad, or Mac. Since this flaw can be combined with CVE-2025-20700 and CVE-2025-20702 for more intrusive Bluetooth control, it matters for users’ privacy and device safety.
PoC publicBeats Studio Buds - BleepingComputer
- SecurityWeekAtlassian, Splunk Patch Critical VulnerabilitiesPatchAtlassian Bamboo Data Center and Server
- SecurityWeekCritical Command Execution Vulnerability Patched in Cisco ISEPatchCisco Identity Services Engine (ISE)