Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Friday, Jun 1215 stories
- SecurityWeekIn Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
CISA added CVE-2026-42271, a command injection issue affecting BerriAI LiteLLM (an AI gateway), to its Known Exploited Vulnerabilities catalog after evidence of active exploitation, making urgent patching important. Separately, South Korea’s PIPC issued a record $400 million penalty to Coupang after security and data-handling failures exposed personal information of more than 30 million customers. In a major enforcement action, an international operation dismantled AudiA6, disrupting a crypto laundering pipeline tied to ransomware financing and seizing related infrastructure and forums.
Roundup - Rapid7 BlogActive Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Oracle has released an out-of-band fix for CVE-2026-35273, a critical remote code execution issue in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools, affecting PeopleTools versions 8.61 and 8.62. Security researchers report the flaw was exploited in the wild as a zero-day prior to Oracle’s June 10, 2026 advisory, with targeting observed from May 27 through June 9, 2026. This matters because attackers leveraged the weakness to reach PeopleSoft endpoints associated with /PSEMHUB/hub and /PSIGW/HttpListeningConnector, enabling compromise and follow-on activity such as data theft and operational tooling deployment.
Reported exploitedPeopleSoft Enterprise PeopleTools - The Hacker NewsLangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
Security researchers disclosed and LangGraph maintainers have patched three issues in LangGraph that can be chained into remote code execution for self-hosted deployments using the SQLite or Redis checkpointer. The affected vulnerabilities are CVE-2025-67644, CVE-2026-28277, and CVE-2026-27022, which respectively involve SQL injection in SQLite checkpoints, unsafe msgpack deserialization, and a RediSearch query injection in @langchain/langgraph-checkpoint-redis. This matters because the chain can allow attackers to turn tampered checkpoint data into server-side code execution, potentially exposing runtime secrets or other connected systems.
PatchLangGraph - SecurityWeekIvanti Sentry Exploitation Attempts Hitting HoneypotsAdvisoryIvanti Sentry
- BleepingComputerCISA orders feds to patch actively exploited Ivanti flaw by Sunday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to patch an actively exploited Ivanti Sentry vulnerability within three days under Binding Operational Directive (BOD) 26-04. The issue, CVE-2026-10520, affects Ivanti's security gateway appliance (formerly known as MobileIron Sentry) and involves an OS command injection weakness that enables attackers to execute code. CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities (KEV) catalog after reports of widespread in-the-wild exploitation attempts, with security researchers warning that potentially unpatched systems are likely already compromised.
Reported exploitedIvanti Sentry - SecurityWeekGoogle Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
Google confirmed that ShinyHunters has exploited an Oracle-mitigated PeopleSoft flaw as a zero-day for data theft. The issue is tracked as CVE-2026-35273, a critical unauthenticated remote code execution vulnerability affecting PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, along with PeopleSoft Enterprise Applications, where Oracle released an out-of-band advisory and mitigations but patches do not appear to be available. Mandiant and Google Threat Intelligence Group observed activity tied to the exploitation from May 27 to June 9, with targeting reportedly concentrated in education and the University of Nottingham named as a confirmed victim.
Reported exploitedPeopleSoft Enterprise PeopleTools - watchTowr LabsMarking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)Reported exploitedCheck Point Mobile Access/SSL VPN
- Daily CyberSecurity (securityonline.info)Multiple Security Flaws Fixed in Major Framework Release
The maintainers of Spring have released security fixes addressing several serious vulnerabilities in Spring components that could allow attackers to manipulate server behavior and compromise applications. Affected CVEs include CVE-2026-41003 (cross-site scripting via Spring Security form rendering), CVE-2026-40999 (outbound request handling that can enable SSRF-style access to internal targets), and CVE-2026-40998 (XML external entity-related attack surface due to unsafe expression evaluation). Enterprise teams should upgrade to the corrected Spring versions (7.0.6 or 6.5.11) as soon as possible to reduce the risk of active exploitation.
PatchSpring Framework - Daily CyberSecurity (securityonline.info)Chrome 149 Patches 28 Flaws, Several Critical UAF Bugs
Google has released Chrome 149.0.7827.114/.115 for Windows and Mac (and 149.0.7827.114 for Linux) to address 28 security vulnerabilities. The update includes multiple critical use-after-free issues in components such as Core, DigitalCredentials, WebMIDI, and Media, tracked as CVE-2026-12007, CVE-2026-12008, CVE-2026-12011, and CVE-2026-12013, along with CVE-2026-12009 (Accessibility input validation) and CVE-2026-12010 (GPU heap buffer overflow). Because these flaws could enable crashes or code execution, updating promptly matters for users and organizations running Chrome.
PatchChrome 149.0.7827.114/.115 (desktop) - Daily CyberSecurity (securityonline.info)Critical 9.9 CVSS Ubiquiti UniFi OS Vulnerabilities Exposed
Ubiquiti has disclosed multiple critical vulnerabilities in UniFi OS affecting several products, including UDM, UDR, UNVR, and Express network models. Tracked CVE IDs include CVE-2026-47367, CVE-2026-47369, CVE-2026-47370, CVE-2026-47368, and CVE-2026-48610, with issues ranging from command injection to path traversal and broken access control. Because attackers may achieve high-impact control such as remote exploitation, privilege escalation, or unauthorized configuration changes, administrators should update UniFi OS Server to version 5.1.15 and UID Enterprise Agent to version 1.61.4 as soon as possible.
PatchUniFi OS Server 5.1.15 - Daily CyberSecurity (securityonline.info)ShinyHunters Strikes with Oracle PeopleSoft ExploitReported exploitedOracle PeopleSoft Environment Management Hub
- Daily CyberSecurity (securityonline.info)New Patches Fix Broad AMD Security Vulnerabilities
AMD has released updates addressing multiple hardware security vulnerabilities that can weaken isolation and allow unauthorized access in certain scenarios. The advisories cover issues tracked as CVE-2025-54509 (related to cache coherency behavior impacting secure memory checks) and CVE-2025-10263 (a translation/memory-access flaw with a high severity CVSS), impacting affected AMD platform firmware/BIOS components—especially on selected EPYC generations. This matters because successful exploitation could enable an attacker to bypass intended protections and potentially access or run untrusted code.
PatchAMD EPYC (4th/5th gen platforms referenced) - Daily CyberSecurity (securityonline.info)Apache Answer Vulnerabilities and Security Flaws Fixed
Apache Answer has released security fixes for several high-impact flaws, including CVE-2026-25688, CVE-2026-25700, CVE-2026-25699, CVE-2026-33582, and CVE-2026-34033. The issues include cross-site scripting, improper handling of security tokens after profile changes, private data exposure via the Timeline API, a crash caused by malicious TIFF uploads, and HTML injection into email alerts. Organizations using Apache Answer should update promptly to reduce risks to user data, account access, and service availability.
PatchApache Answer 2.0.1 - Daily CyberSecurity (securityonline.info)Millions at Risk: 9.8 CVSS Remote Code Execution in HTTP.sysPatchWindows (HTTP.sys)
- Daily CyberSecurity (securityonline.info)New Patches Secure Critical Spring HATEOAS FlawsPatchSpring HATEOAS
Thursday, Jun 1124 stories
- The Hacker NewsShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach UniversitiesReported exploitedOracle PeopleSoft Enterprise PeopleTools
- BleepingComputerOracle mitigates PeopleSoft zero-day exploited in data theft attacksReported exploitedOracle PeopleSoft PeopleTools 8.61/8.62
- Dark ReadingMax-Severity Ivanti Flaw Exploited 24 Hours After DisclosureReported exploitedIvanti Sentry (Sentry mobile gateway)
- The Hacker News
- The Hacker NewsThe Gentlemen Ransomware Claims 478 Victims, Can Spread Like a WormReported exploitedThe Gentlemen
- SecurityWeekOracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day AttacksAdvisoryPeopleSoft Enterprise PeopleTools
- Check Point ResearchFrom SQLi to RCE – Exploiting LangGraph’s Checkpointer
Check Point Research reports three flaws in LangGraph’s persistence layer (checkpointers), impacting the SQLite checkpointer (CVE-2025-67644 and CVE-2026-28277) and the Redis checkpointer (CVE-2026-27022). In the SQLite path, a filter-related SQL injection can be chained with unsafe msgpack deserialization to reach remote code execution, since attacker-supplied checkpoint data is deserialized during state history retrieval. This matters most for teams self-hosting LangGraph and exposing getstatehistory() with a user-controlled filter; LangChain’s managed LangSmith Deployment using PostgreSQL is not affected. Fixes are available in langgraph-checkpoint-sqlite 3.0.1+, langgraph 1.0.10+, and langgraph-checkpoint-redis 1.0.2+.
ResearchLangGraph - The Hacker NewsThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories
A public release of the Miasma supply-chain attack toolkit (assessed as a variant of the Shai-Hulud worm) has been linked to credential theft affecting software ecosystems across PyPI, npm, RubyGems, JFrog Artifactory, GitHub repositories and GitHub Actions, with follow-on evolution toward a Python variant called Hades. The same roundup also highlights “Ghost-Sender” email spoofing risks in certain Microsoft Exchange configurations and “Pinchy” AI email-agent phishing weaknesses in OpenClaw that can trick agents into forwarding sensitive AWS IAM keys, database passwords, and SSH access. No specific CVE IDs were provided in the report, but the incidents matter because they target identities, build pipelines, and autonomous agent workflows where traditional defenses can lag.
- SecurityWeekHackers Exploit Langflow Vulnerability for Remote Code ExecutionReported exploitedLangflow
- SecurityWeekSplunk, Palo Alto Networks Patch Severe VulnerabilitiesPatchSplunk Enterprise
- Daily CyberSecurity (securityonline.info)Multiple Security Flaws Addressed in Core Java Application SubsystemsPatchSpring GraphQL
- SecurityWeekMicrosoft Patches Exploited Exchange Server Vulnerability
Microsoft has released Patch Tuesday updates to address an Exchange Server vulnerability that is already being exploited in the wild, tracked as CVE-2026-42897. The flaw affects Exchange Server Subscription Edition, 2016, and 2019, and could be triggered via a specially crafted email leading to spoofing and cross-site scripting that allows JavaScript execution in a victim’s browser context. CISA added CVE-2026-42897 to its Known Exploited Vulnerabilities (KEV) catalog, requiring remediation by May 29, underscoring the urgency for organizations using affected Exchange deployments to apply the June 9 patches.
Reported exploitedExchange Server - BleepingComputerMax severity Ivanti Sentry vulnerability now exploited in attacksReported exploitedIvanti Sentry
- Daily CyberSecurity (securityonline.info)PeopleSoft RCE Security Bug: New Oracle Fix
Oracle has issued an emergency update for a PeopleSoft remote code execution vulnerability that can be triggered over the network without authentication. The issue affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 and is tracked as CVE-2026-35273 (CVSS 9.8), enabling attackers with HTTP access to take over systems, alter databases, and execute arbitrary commands. Organizations running affected deployments should apply Oracle’s patched update immediately and validate that exposed instances are remediated.
PatchPeopleSoft Enterprise PeopleTools - Daily CyberSecurity (securityonline.info)Splunk Enterprise Vulnerabilities: Patch CVSS 9.8 FlawsPatchSplunk Enterprise
- Daily CyberSecurity (securityonline.info)Dahua Product Vulnerabilities: Patch 3 Critical CVEs
Dahua’s advisory DHCC-SA-202606-001 reports multiple severe security issues across certain Dahua IP cameras (IPC), PTZ cameras (SD), network video recorders (NVR), and related hardware. The affected CVE IDs are CVE-2026-29114 (certificate trust chain weakness), CVE-2026-29115 (authenticated remote denial of service), and CVE-2026-29116 (unauthenticated remote denial of service via specially crafted packets). These flaws matter because they can enable attackers to undermine certificate-based trust and repeatedly disrupt surveillance availability, putting enterprise physical security networks at risk.
PatchIP cameras - Daily CyberSecurity (securityonline.info)ITScape KVM Escape: Public PoC Exploit Threatens Cloud Hosts
A proof-of-concept for an ITScape KVM escape issue has been publicly released, tracked as CVE-2026-46316. The flaw impacts KVM/arm64 environments by enabling untrusted guest virtual machines to break isolation and execute commands on the host with kernel (root) privileges. Because the bug resides in-kernel KVM and can be triggered from guest-side actions, it significantly raises risk for multi-tenant public cloud providers and tenants running affected kernel versions.
PoC publicKVM/arm64 (ITScape) - Daily CyberSecurity (securityonline.info)Critical Jenkins Security Advisory 2026: Patch Multiple Flaws
A new Jenkins security advisory released in 2026 reports several high-impact issues affecting Jenkins, including remote code execution and data exposure via deserialization (CVE-2026-53435) and additional open redirect and XSS-related weaknesses (CVE-2026-53436, CVE-2026-53437, CVE-2026-53441). The advisory also addresses missing authorization checks and information leakage that can let attackers disrupt job queues, view sensitive user data, and extract plaintext secrets from POST config.xml submissions (CVE-2026-53438, CVE-2026-53439, CVE-2026-53442). Because these flaws can be exploited against CI/CD deployments, Jenkins administrators should apply the published patches immediately—upgrading to version 2.568 for weekly releases or 2.555.3 for LTS.
PatchJenkins - Daily CyberSecurity (securityonline.info)Important GitLab Security Updates Address 12 Vulnerabilities
GitLab released security updates for self-managed Community and Enterprise Editions, including versions 19.0.2, 18.11.5, and 18.10.8, addressing 12 vulnerabilities. The fixes include high-impact issues such as CVE-2026-6552 (improper access control in Group SAML Identity API), CVE-2026-10087 (XSS in the Analytics Dashboard), CVE-2026-7250 (unauthenticated DoS), and multiple injection/authorization problems like CVE-2026-8589 and CVE-2026-10733. Administrators should upgrade promptly because these bugs can enable account takeover, execute client-side code, disrupt availability, and expose or alter sensitive data.
PatchGitLab Community Edition - Daily CyberSecurity (securityonline.info)Critical NVIDIA DALI Vulnerabilities Require Immediate Action
NVIDIA has released a June 2026 security update for NVIDIA DALI addressing two critical issues affecting versions 0.0 through 2.0. The flaws are tracked as CVE-2026-24180 (heap-based buffer overflow) and CVE-2026-24181 (improper index validation), and successful exploitation could enable code execution, data tampering, denial of service, or information disclosure across any supported platform/OS. Organizations using NVIDIA DALI should update to DALI v2.1 or later immediately to reduce exposure.
PatchNVIDIA DALI - Daily CyberSecurity (securityonline.info)PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
A critical remote code execution issue tracked as CVE-2026-45034 has been disclosed in PhpSpreadsheet (PHPOffice), along with public proof-of-concept exploit details. The problem stems from a patch-bypass weakness in File::prohibitWrappers that attackers can evade by manipulating wrapper input, allowing dangerous file handling and, depending on the PHP version and application behavior, potential deserialization to reach RCE. Versions in the 1.x series up to 1.30.4 are reported as vulnerable, and upgrading to 1.30.5 is recommended to reduce exposure.
PoC publicPhpSpreadsheet - Daily CyberSecurity (securityonline.info)strongSwan CVE-2026-47895: Double-Free Exploit ExplainedPatchstrongSwan
- Daily CyberSecurity (securityonline.info)Spring Data Vulnerabilities: Patch Five Critical Flaws NowPatchSpring Data REST
- MandiantShinyHunters Targets Education Sector with Oracle PeopleSoft ExploitReported exploitedOracle PeopleSoft Environment Management Hub (PSEMHUB)
Wednesday, Jun 101 story
- Daily CyberSecurity (securityonline.info)Critical UpdraftPlus CVE-2026-10795 Exploit Targets MillionsReported exploitedUpdraftPlus (UpdraftCentral integration)