Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Wednesday, Jun 1030 stories
- BleepingComputerPath traversal flaw in AI dev platform Langflow exploited in attacksReported exploitedLangflow
- The Hacker NewsChina-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Security researchers report a resurgence and expansion of the JDY botnet, a covert network attributed to China-nexus state-sponsored threat activity. JDY now targets more than 1,500 SOHO and IoT devices and operates as a centralized scanner to discover, fingerprint, and continuously map exposed services for later exploitation. The activity includes use of edge-device vulnerabilities such as CVE-2026-35616, highlighting ongoing risk to internet-facing infrastructure and the persistence of reconnaissance capabilities even after related takedowns.
ResearchJDY botnet (scanner malware) - The Hacker News
- The Hacker NewsUnpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
Security researchers report that an unpatched vulnerability in Langflow, an open-source low-code AI application platform, is being exploited in the wild. CVE-2026-5027 (CVSS 8.8) is a path traversal issue that can allow arbitrary file writes via the POST /api/v2/files endpoint, and unauthenticated access can be sufficient to reach the vulnerable code path before exploitation. This matters because it enables remote compromise without valid credentials, adding to a series of active Langflow attacks this year tied to CVE-2026-0770, CVE-2026-33017, CVE-2026-21445, and CVE-2025-34291.
Reported exploitedLangflow - BleepingComputerChina-linked JDY botnet expands targeting of U.S. military networksReported exploitedJDY botnet
- The Hacker NewsCISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after reports of in-the-wild exploitation, affecting Cisco Catalyst SD-WAN Manager, Google Chrome V8, and Arista Extensible Operating System (EOS). The listed issues are CVE-2026-20245 (Cisco; authenticated local command execution as root), CVE-2026-11645 (Chrome V8; sandbox escape via crafted HTML for remote code execution), and CVE-2026-7473 (Arista EOS; improper handling of tunnel traffic that can process unexpected tunneled packets). It matters because the KEV listing signals active attacker use, and federal civilian agencies have been directed to remediate or mitigate by June 23, 2026.
Reported exploitedCisco Catalyst SD-WAN Manager - BleepingComputerMicrosoft patches Exchange Server zero-day exploited in attacks
Microsoft released security updates for a zero-day in Microsoft Exchange Server that has been exploited in real-world attacks, enabling attackers to run arbitrary JavaScript via a cross-site scripting (XSS) path that targets Outlook Web Access users. The issue, tracked as CVE-2026-42897, affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE), and can be triggered remotely by sending a crafted email without special privileges. This matters because the flaw allows malicious script execution in the victim’s browser context, increasing the risk of account and session compromise; defenders should apply the June 2026 fixes and keep the related mitigations enabled.
Reported exploitedExchange Server 2016 - SecurityWeekNew Windows Zero-Day Exploit ‘RoguePlanet’ ReleasedPoC publicWindows
- Rapid7 Blog
- BleepingComputer
- The Hacker News
- SecurityWeekCritical Vulnerabilities Patched in Fortinet, Ivanti ProductsPatchFortiSandbox
- Daily CyberSecurity (securityonline.info)COXMO Botnet Variant: New Advanced Threat Exploits Router FirmwareReported exploitedCOXMO botnet variant
- SecurityWeek
- The Hacker News
- SecurityWeekNo Patch Planned for Exploited Arista EOS VulnerabilityReported exploitedArista EOS
- BleepingComputerIvanti: Max severity Sentry flaw allows code execution as rootPatchIvanti Sentry
- The Hacker NewsMicrosoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated WindowsPoC publicMicrosoft Defender
- The Hacker NewsSix Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
Researchers disclosed six security issues in protobuf.js (often used with Google Cloud client libraries, Baileys, and CI/CD workflows), collectively dubbed Proto6. The vulnerabilities affect Node.js services that deserialize attacker-controlled Protobuf data or generate code from schemas, enabling remote code execution and denial-of-service conditions. Affected CVEs include CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, and CVE-2026-44295, with the most critical RCE risk tied to CVE-2026-44291; patches are available in protobufjs 7.5.6 and 8.0.2, and protobufjs-cli 1.2.1 and 2.0.2.
Researchprotobuf.js - Daily CyberSecurity (securityonline.info)Ivanti Sentry RCE: Publicly Disclosed PoC for CVSS 10
Ivanti has published urgent fixes for its gateway appliances after researchers and watchTowr Labs disclosed a publicly available proof of concept for an Ivanti Sentry remote code execution issue. The affected component is associated with CVE-2026-10520 (CVSS 10), and a related authentication/privilege bypass is tracked as CVE-2026-10523 (CVSS 9.9), which can enable creation of administrative accounts and full administrative access. Because these systems sit at the edge of corporate traffic, unpatched deployments face a heightened risk of full administrative compromise; organizations should review logs and upgrade to versions 10.5.2, 10.6.2, or 10.7.1 immediately.
PoC publicIvanti Sentry - Daily CyberSecurity (securityonline.info)OpenSSL Security Patches Fix Remote Code Execution Risk
OpenSSL has released emergency security updates to fix multiple memory-safety flaws in its certificate and QUIC-related code paths, including a use-after-free that can be triggered remotely and lead to Remote Code Execution via CVE-2026-45447. The release also covers additional security issues such as input-validation weaknesses (CVE-2026-34182), nonce handling problems in AES-OCB one-shot operations (CVE-2026-45445), and denial-of-service and crash conditions in the QUIC stack (CVE-2026-34183, CVE-2026-42764, CVE-2026-42765) plus an OCSP stapling double-free hazard (CVE-2026-35188). OpenSSL users are urged to upgrade promptly—e.g., from version 4.0 to version 4.0.1, and from 1.1.1 to 1.1.1zh—because unauthenticated attackers may be able to exploit these problems over the network.
PatchOpenSSL - Daily CyberSecurity (securityonline.info)CISA Expands Active Exploit Catalog with Cisco, Arista, and Chromium Flaws
The US CISA has updated its Known Exploited Vulnerabilities catalog/active exploit list by adding three newly identified, in-the-wild flaws. Affected products include Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Arista EOS (CVE-2026-7473), and Google Chromium (CVE-2026-11645), spanning command-injection, tunneling/decapsulation weaknesses, and memory-safety issues that can lead to remote code execution. Because attackers are already targeting these weaknesses, organizations should prioritize patching and remediation immediately.
Reported exploitedCisco Catalyst SD-WAN Manager - Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)High-Severity Vulnerabilities Addressed in Endpoint Manager MobilePatchIvanti Endpoint Manager Mobile (EPMM)
- Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Critical Veeam Backup Vulnerability ExposedPatchVeeam Backup & Replication
- Daily CyberSecurity (securityonline.info)Critical FortiSandbox Flaw Requires Immediate PatchingPatchFortiSandbox
- Daily CyberSecurity (securityonline.info)
- watchTowr Labs
- Daily CyberSecurity (securityonline.info)MBS Universal Gateway Flaws Threaten Building Automation Networks
MBS GmbH disclosed multiple critical security issues in its MBS Universal Gateway devices affecting firmware version V6005 and earlier, including unauthenticated access via a default credential weakness tracked as CVE-2026-35075 (CVSS 9.8) and remotely exploitable stack buffer overflow problems tracked as CVE-2026-35085, CVE-2026-35084, and CVE-2026-35083. The flaws could allow attackers to obtain full root control and, in some cases, read sensitive logs, placing smart building perimeter networks at risk. Administrators should update affected gateways to V6007 immediately to reduce the likelihood of compromise.
AdvisoryMBS Universal Gateway
Tuesday, Jun 910 stories
- Krebs on SecurityA Record-Breaking Patch Tuesday for June 2026RoundupWindows
- Dark ReadingBlame AI: Patch Tuesday Hits Record 206 CVEsRoundupWindows
- Cisco Talos
- Rapid7 BlogRapid7RoundupWindows
- Ars Technica (Security)Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosedPoC publicWindows Collaborative Translation Framework (CTFMON)
- Qualys Security BlogMicrosoft and Adobe Patch Tuesday, June 2026 Security Update ReviewRoundupMicrosoft Windows
- BleepingComputerSAP fixes critical flaws in NetWeaver and Commerce CloudPatchSAP NetWeaver
- SecurityWeekMicrosoft Patches 200 VulnerabilitiesPatchMicrosoft Windows
- BleepingComputerMicrosoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsReported exploitedWindows Collaborative Translation Framework (CTFMON)
- BleepingComputerMicrosoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsPatchWindows Collaborative Translation Framework (CTFMON)