1. A critical remote code execution vulnerability in the ServiceNow AI Platform identified as CVE-2026-6875 is currently being exploited in the wild (BleepingComputer). 2. The Hugging Face AI model repository suffered a data breach after an autonomous AI agent gained unauthorized access to internal datasets and credentials (The Hacker News). 3. WordPress core vulnerabilities collectively known as wp2shell are being actively exploited to achieve remote…
Posts tagged as “botnet”
1. CISA added a critical Splunk Enterprise remote code execution vulnerability CVE-2026-20253 to its known exploited vulnerabilities catalog after reports of active exploitation (https://www.reddit.com/r/cybersecurity/comments/1ua3npz/cisa_adds_splunk_enterprise_rce_cve202620253_to/). 2. International law enforcement agencies disrupted the SocGholish botnet infrastructure and cleaned nearly 15000 infected WordPress sites in an operation linked to the Evil Corp cybercrime group (https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html). 3. CISA issued a warning regarding the FortiBleed campaign which has compromised over…
1. Miasma malware has impacted 73 Microsoft GitHub repositories leading to security concerns regarding repository integrity (Reddit). 2. Threat actor UNC3753 is conducting a financially motivated data theft and extortion campaign against U.S. professional and financial services (The Hacker News). 3. Over 20000 Instagram accounts were hijacked after attackers abused Meta AI support systems to reset user passwords (Bleeping Computer). 4. Hackers are actively exploiting…
1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, is under active exploitation in the wild. (The Hacker News) 2. Attackers are actively exploiting the GlobalProtect authentication bypass flaw to establish unauthorized VPN connections to corporate networks. (BleepingComputer) 3. A new local privilege escalation vulnerability named CIFSwitch has been identified in the Linux kernel, allowing attackers to gain root access…
1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS and Prisma Access, is currently under active exploitation (thehackernews.com). 2. Dutch authorities successfully dismantled a massive botnet consisting of 17 million infected devices and seized over 200 associated servers (bleepingcomputer.com). 3. A Russian-linked threat actor named GREYVIBE has been identified conducting persistent AI-powered cyberattacks against Ukrainian entities since August 2025 (thehackernews.com). 4.…
1. Microsoft confirmed active exploitation of two Microsoft Defender vulnerabilities including CVE-2026-41091 which grants SYSTEM privileges (The Hacker News). 2. CISA added critical vulnerabilities in Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities catalog following evidence of active use (The Hacker News). 3. Cisco patched a maximum severity vulnerability CVE-2026-20223 in Secure Workload that allows unauthenticated remote attackers to access sensitive data…
1. Microsoft Exchange and Windows 11 were successfully compromised by researchers using zero day vulnerabilities during the Pwn2Own Berlin 2026 event (bleepingcomputer.com). 2. The Funnel Builder WordPress plugin is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages to steal credit card data (bleepingcomputer.com). 3. A critical supply chain attack targeting the TanStack library impacted two OpenAI employee devices, prompting immediate security containment…
1. Three Microsoft Defender zero day vulnerabilities codenamed BlueHammer RedSun and UnDefend are being actively exploited in the wild to gain elevated privileges (The Hacker News). 2. The Payouts King ransomware group is utilizing QEMU virtual machines as a reverse SSH backdoor to evade detection by endpoint security solutions (BleepingComputer). 3. The Grinex cryptocurrency exchange has suspended operations following a 13.7 million dollar hack that…
1. A new payment skimmer uses WebRTC data channels to bypass security controls and exfiltrate payment data from e-commerce sites (thehackernews.com). 2. A Magento vulnerability identified as APSB25-94 allows unauthenticated file uploads leading to remote code execution (reddit.com). 3. The GlassWorm malware campaign has evolved to use Solana blockchain dead drops to deliver remote access trojans and steal sensitive browser and crypto data (thehackernews.com). 4.…