Security news, decoded.
73 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Thursday, Jun 186 stories
- ESET WeLiveSecurityKilling me gently: Inside Gentlemen’s EDR killer frameworkReported exploitedAcronis
- SecurityWeekF5 Patches Critical, High-Severity NGINX Vulnerabilities
F5 has issued out-of-band updates to fix multiple NGINX vulnerabilities, including critical issues in HTTP modules tracked as CVE-2026-42530 and CVE-2026-42055. These flaws (CVSS 9.2) could be exploited without authentication to trigger memory corruption (use-after-free or heap-based buffer overflow), potentially leading to denial-of-service and, if ASLR is disabled or bypassable, arbitrary code execution. F5 also patched additional NGINX Gateway Fabric bugs CVE-2026-11311 and CVE-2026-50107 that may let authenticated attackers inject malicious configuration directives, plus other medium-severity NGINX issues affecting memory disclosure or stability.
PatchNGINX Plus - Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Moxa Patches NPort Flaws: Root RCE and Format String Bugs (CVE-2026-10829)PatchMoxa NPort W2150A-W4 Series
- Daily CyberSecurity (securityonline.info)i18next Prototype Pollution Flaw (CVSS 9.1) Threatens 1M+ Weekly DownloadsPatchi18next-fs-backend
- Daily CyberSecurity (securityonline.info)Zyxel Patches Stack-Based Buffer Overflow in GS1900 Switches (CVE-2026-7273)
Zyxel has released firmware updates to address a stack-based buffer overflow in its GS1900 series switches, tracked as CVE-2026-7273 and scored 8.8 (CVSS). The issue impacts the GS1900-8, GS1900-24, and GS1900-48HPv2, among other GS1900 models running firmware version 2.90 or earlier, and could allow a LAN-based, unauthenticated attacker to execute commands and potentially take control of the device. Because affected switches are often central to network operations, patching promptly is important to reduce the risk of intrusion and lateral movement.
PatchGS1900 series switches
Wednesday, Jun 1722 stories
- Dark ReadingINC Ransomware Thrives by Mastering the BasicsResearchAcronis
- Daily CyberSecurity (securityonline.info)Splunk AI Toolkit Vulnerabilities: Critical RCE & Data RisksPatchSplunk AI Toolkit
- Daily CyberSecurity (securityonline.info)Active Gravity SMTP Vulnerability Exploited in the Wild
A vulnerability in RocketGenius Gravity SMTP is being exploited in the wild, tracked as CVE-2026-4020 (CVSS 7.5). The issue affects Gravity SMTP versions ≤ 2.1.4 by allowing unauthenticated attackers to access a REST API endpoint that returns system report details, including sensitive email integration credentials (API keys, secrets, and OAuth tokens). This matters because exposed credentials can enable account compromise and follow-on spam or phishing activity; affected users should upgrade to Gravity SMTP 2.1.5 and rotate any email integration secrets.
Reported exploitedGravity SMTP - Daily CyberSecurity (securityonline.info)Cisco ISE Vulnerabilities: Critical RCE and Info Disclosure FlawsPatchCisco Identity Services Engine (ISE)
- The Hacker NewsMicrosoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in DevelopmentPoC publicMicrosoft Defender
- Daily CyberSecurity (securityonline.info)Critical Apache Shiro LDAP Injection Flaw Uncovered
Researchers identified a critical LDAP injection issue in Apache Shiro’s DefaultLdapRealm that could let attackers bypass authentication by manipulating the LDAP Distinguished Name (DN) construction. The vulnerability is tracked as CVE-2026-49268 and affects Apache Shiro versions below 2.2.1, as well as versions 3.0.0-alpha-0 through 3.0.0-alpha-1, with a high CVSS score of 8.8. Organizations should remediate by updating to Apache Shiro 2.2.1 or later (or 3.0.0-alpha-2 and later) to prevent impersonation and unauthorized access.
PatchApache Shiro - SecurityWeekRockwell Automation Patches Vulnerabilities in ICS Controllers and Software
Rockwell Automation has released security updates for vulnerabilities in several ICS products, including Logix and CompactLogix controllers, Flex I/O dual-port Ethernet/IP adapters, RSLinx, and the FactoryTalk automation suite. The advisories address issues such as authentication bypass and denial-of-service risks in FactoryTalk Historian Site Edition (CVE IDs not specified in the article), improper API authorization in FactoryTalk Analytics PavilionX, multiple DoS flaws in certain CompactLogix/ControlLogix and GuardLogix controllers (including CVE IDs not specified), and a critical adapter weakness that could let an unauthenticated attacker reset a web interface password. While Rockwell noted in-the-wild exploitation of an older issue tracked as CVE-2021-22681, the article says the newly patched vulnerabilities have not yet been targeted by threat actors.
PatchLogix - BleepingComputerCISA orders feds to patch max severity Joomla plugin flaw by FridayReported exploitedWidget Factory Joomla Content Editor (JCE) plugin
- SecurityWeekMicrosoft Working on Patch for ‘RoguePlanet’ Zero-Day
Microsoft has acknowledged a publicly disclosed privilege-escalation flaw in Microsoft Defender’s Microsoft Malware Protection Engine, tracked as CVE-2026-50656 (CVSS 7.8). The issue, dubbed “RoguePlanet,” is linked to a race condition that can let attackers elevate privileges to System on Windows 10 and Windows 11, and it matters because it turns Defender into a local elevation vector. Microsoft says it is working on a high-quality security update to address CVE-2026-50656 and will provide details once the fix is available.
PoC publicMicrosoft Defender - SecurityWeekOracle’s Second Monthly Security Updates Deliver 245 PatchesPatchOracle Communications
- Daily CyberSecurity (securityonline.info)JDY Botnet Resurges: China-Nexus IoT Army Hunts New Vulnerabilities Within Hours
Black Lotus Labs reports that the China-nexus JDY botnet has grown and is again scanning the internet for newly disclosed vulnerabilities within hours, using masked infrastructure and scanning techniques designed to blend into normal traffic. Compromised devices include Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, and the activity is notably tied to Fortinet systems following publication of CVE-2026-35616. The fast weaponization window matters because edge and embedded deployments are often harder to monitor and patch, increasing the chance of pre-patch probing and exploitation.
Reported exploitedJDY botnet - BleepingComputerMicrosoft working on Defender patch for RoguePlanet zero-dayPoC publicMicrosoft Defender
- Daily CyberSecurity (securityonline.info)AdGuard Email Tracking Protection: Stop Hidden Pixels
AdGuard has released a new email filtering capability (AdGuard Email Tracking Protection) designed to stop hidden 1×1 pixel trackers in messages that reveal when an email is opened and can expose client and device details. This matters because many marketing campaigns rely on these “invisible” image loads to measure engagement and track recipients. The article also references AdGuard’s ongoing security work, including CVE-2024-36814, underscoring that privacy and protection features are now a focus across its product updates.
AdvisoryAdGuard email tracking protection - SecurityWeekJoomla, LiteSpeed Vulnerabilities Exploited in Attacks
Attackers are exploiting security weaknesses in Joomla’s Content Editor (JCE) and the LiteSpeed cPanel plugin to gain code execution and escalate privileges. Joomla JCE Pro versions before 2.9.99.5 are affected by CVE-2026-48907, enabling unauthenticated abuse to upload arbitrary files and run PHP code; fixes were released in 2.9.99.5 and strengthened again in 2.9.99.6. Separately, LiteSpeed’s user-end cPanel plugin versions before 2.4.8 are impacted by CVE-2026-54420, where improper symlink handling can let attackers escalate to root on shared hosting running CloudLinux/CageFS; both issues have been added to CISA’s KEV catalog, underscoring the urgency to patch.
Reported exploitedJoomla Content Editor (JCE) Pro - SecurityWeek3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker CrosshairsReported exploitedFortiSandbox
- The Hacker NewsCISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionReported exploitedWidget Factory Joomla Content Editor (JCE)
- Daily CyberSecurity (securityonline.info)Chrome Security Update Fixes 33 Flaws, Seven Critical
Google has released a major security update for the Google Chrome 149 desktop browser, fixing 33 vulnerabilities in total, with seven rated “Critical.” The Stable channel has moved to 149.0.7827.155/.156 for Windows and Mac, and Linux receives 149.0.7827.155; several top issues are use-after-free memory corruption flaws that can enable remote code execution. Notable CVEs include CVE-2026-12437 (WebShare), CVE-2026-12442 (Passwords), CVE-2026-12443 (Web Authentication), CVE-2026-12439 and CVE-2026-12440 (Digital Credentials), making prompt patching important.
PatchGoogle Chrome Stable 149.0.7827.155/.156 - Daily CyberSecurity (securityonline.info)Fortra BoKS Vulnerability Opens Door to Remote Command InjectionAdvisoryFortra BoKS
- Daily CyberSecurity (securityonline.info)Critical Yarbo Robot Vulnerability Exposes Global Fleet
Researchers report that Yarbo Android and iOS apps contain hard-coded MQTT credentials, tracked as CVE-2026-10557, which can be extracted from the apps and used to access MQTT brokers supporting a large global robot fleet. A second issue, CVE-2026-7368, is a lack of proper per-device/per-user authorization in the Yarbo cloud, meaning a single valid login could allow fleet-wide access. This matters because attackers may be able to subscribe to telemetry and issue commands across many robots rather than affecting only one device.
AdvisoryYarbo Android app - Daily CyberSecurity (securityonline.info)Cloud Foundry UAA Vulnerability Enables SAML Authentication BypassAdvisoryCloud Foundry UAA
- Daily CyberSecurity (securityonline.info)NVIDIA Patches Three High-Severity NeMo Framework Code Injection Flaws
NVIDIA has released an urgent security update for its NeMo Framework, addressing three High-severity code-injection-related flaws: CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228. The issues can enable remote or local code execution depending on the CVE, including potential privilege escalation and data tampering, and affect all NeMo versions from 0.0 up to 2.7.2. Users should upgrade to version 2.7.3 or later to reduce the risk of exploitation, especially on shared training or AI pipeline infrastructure.
PatchNVIDIA NeMo Framework - Daily CyberSecurity (securityonline.info)MongoDB Server Vulnerability Wave Hits Document Databases
MongoDB Server has disclosed a new set of security issues affecting document databases, with fixes covering several MongoDB release lines (including 7.0, 8.0, 8.2, and 8.3). The advisories include CVE-2026-11933 (use-after-free in server-side JavaScript that can leak memory or crash when reachable by an authenticated user), CVE-2026-9740 (an unauthenticated denial-of-service crash via BSON validation recursion), CVE-2026-9750 and CVE-2026-9743 (authenticated and aggregation-related crash or incorrect-results scenarios). Because at least one bug can be triggered without authentication, upgrading to the provided fixed versions such as 8.0.26, 8.2.11, and 8.3.4 is a priority.
PatchMongoDB
Tuesday, Jun 1612 stories
- The Hacker NewsGoogle Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
Google Cloud Vertex AI SDK for Python contained a bug that let an attacker with their own Google Cloud project and the victim’s project ID hijack model uploads and get code to execute in Google’s model serving infrastructure. The issue is in the SDK’s default temporary Cloud Storage bucket handling, enabling cross-tenant model replacement (notably for pickle/joblib-based models) and theft of OAuth tokens from the serving container; Unit 42 reported the risk and Google patched it in v1.148.0 (update from versions such as 1.139.0 and 1.140.0). No CVE has been published for this specific problem as of the article’s publication, but users should upgrade and explicitly set stagingbucket to a bucket they control.
PatchVertex AI SDK for Python - Daily CyberSecurity (securityonline.info)ShapedPlugin Supply Chain Attack Exposes WordPress Sites
Researchers say a ShapedPlugin supply chain attack compromised the vendor’s distribution pipeline and inserted malicious backdoor code into premium Pro plugin releases, impacting WordPress sites that update normally. The activity is tracked under CVE-2026-10735 and CVE-2026-49777, with confirmed exposure including Real Testimonials Pro version 3.2.5 plus other premium plugins such as Product Slider Pro and Smart Post Pro. This matters because the malware also targets authentication (including 2FA/TOTP secrets), potentially allowing attackers to bypass multi-factor protections.
Reported exploitedPro plugin releases - Bishop Fox
- BleepingComputerCISA warns of another cPanel plugin flaw exploited in attacks
CISA has directed U.S. federal agencies to patch within three days a actively exploited vulnerability in the LiteSpeed cPanel user-end plugin, tracked as CVE-2026-54420. Reported as CVE-2026-48172, the high-severity flaw affects user-end plugin versions before 2.4.8 and can let attackers with FTP or web shell access escalate to root on shared hosting systems running CloudLinux/CageFS due to a UNIX symlink-following issue. This is included in CISA’s Known Exploited Vulnerabilities Catalog, making timely remediation critical to reduce the risk of widespread compromise.
Reported exploitedLiteSpeed cPanel user-end plugin - The Hacker NewsAttackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last WeekReported exploitedFortiSandbox
- BleepingComputerRansomware gang abuses Microsoft Teams relays to hide malicious trafficReported exploitedMicrosoft Teams
- The Hacker NewsChina-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Researchers report two new Windows builds of the SprySOCKS backdoor—tracked internally as WINDRV and WINPLUS—previously believed to target Linux. The Windows versions use hard-coded command-and-control with TCP, UDP, and WebSocket communications and expand capabilities for reconnaissance, service/process management, and file operations, with WINDRV leveraging kernel drivers and WINPLUS using the Windows Print Spooler to load the payload more covertly. Evidence suggests UEFI-boot persistence may be involved, potentially exploiting CVE-2023-24932, a Windows Boot Manager security bypass that Microsoft fixed in May 2023.
ResearchSprySOCKS - BleepingComputerCritical Fortinet FortiSandbox flaws now exploited in attacks
Threat actors are reportedly exploiting multiple critical Fortinet FortiSandbox vulnerabilities in the wild, enabling privilege escalation and remote code execution without authentication or user interaction. The affected flaws are tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, and Fortinet released security updates on April 14—organizations should upgrade to the latest fixed versions to stop active attacks. This matters because FortiSandbox weaknesses have previously been leveraged in ransomware and intrusion campaigns to break into target networks.
Reported exploitedFortiSandbox - BleepingComputerWindows version of SprySOCKS Linux malware used to attack govt orgs
ESET found Windows versions of the SprySOCKS backdoor being used in attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras during 2023–2024. The activity is assessed with high confidence as the work of the Earth Lusca threat actor (also tracked as FishMonger, Aquatic Panda, Red Dev 10, and TAG-22), and the malware’s Windows variants add kernel-level stealth plus covert command-and-control through diverted TCP traffic. Researchers also noted signals that a possible UEFI bootkit component could involve CVE-2023-24932 (a Secure Boot issue), which matters because it may indicate additional pre-OS persistence risk alongside the already stealthy Windows backdoors.
ResearchSprySOCKS - Daily CyberSecurity (securityonline.info)Fluffy Wolf Phishing Attacks Push PowerLoader MalwareReported exploitedPowerLoader
- Daily CyberSecurity (securityonline.info)curl Project Pauses Vulnerability Reports for “Summer of Bliss”
The lead maintainer of the curl project announced a temporary halt in accepting vulnerability reports for the period July 1, 2026 (00:00 CEST) through August 3, 2026 (09:00 CEST), including submissions via HackerOne or email. The pause is intended as a scheduled rest rather than a response to a security incident, and it also shifts the planned release of version 8.22.0 to September 2, 2026. While urgent issues may still be handled earlier for companies with paid support contracts, other reports will be deferred, which matters for organizations relying on fast disclosure handling.
Advisorycurl - Daily CyberSecurity (securityonline.info)Inside the Stealthy Agent Tesla Infection Chain
Attackers are using phishing emails that deliver obfuscated script-based loaders to trigger an advanced Agent Tesla infection chain, moving from attachment execution to process injection, stealthy data theft, and exfiltration with minimal user awareness. The article highlights how this modern approach shifts away from older Microsoft Office exploitation commonly associated with CVE-2017-11882, CVE-2017-0199, and CVE-2018-0802, while still referencing CVE-2023-24059 in the context of the observed threat. This matters because the reliance on in-memory payload execution, process hollowing, and anti-analysis checks can make traditional detection harder, increasing the risk of credential and session compromise.
Reported exploitedAgent Tesla