Cyber Security
Cybersecurity
Akira Claims Industrial Finisher, NJ Country Club, Architecture Firm
Andrew Doyle
June 12, 2026
Akira ransomware posted three US victims on June 9: Spray Equipment with 26GB of W-2 records and engineering drawings, Rockaway River Country Club, and SMPC ...
Cybersecurity
Chaos Ransomware Lists Airespring as Iranian False-Flag History Looms
Mitchell Langley
June 12, 2026
Chaos ransomware listed US telecom provider Airespring on its leak site. Rapid7 documented Chaos as a MuddyWater Iranian APT false-flag tool, complicating attribution.
Application Security
Shai-Hulud Hades Wave Poisons 29 Bioinformatics PyPI Packages
Gabby Lee
June 12, 2026
The Shai-Hulud Hades variant targeted ~29 bioinformatics and ML PyPI packages in a second wave, introducing a loader-payload split and bringing the campaign past 100 ...
Application Security
Oracle PeopleSoft CVE-2026-35273: ShinyHunters Breaches 100+ Orgs
Gabby Lee
June 11, 2026
Oracle issued emergency mitigations for CVE-2026-35273, an RCE flaw in PeopleSoft, after ShinyHunters breached 300 instances across more than 100 organizations.
Cybersecurity
Nottingham University Breach Exposes Data on 454,600 Students
Mitchell Langley
June 11, 2026
ShinyHunters posted 40GB of stolen data on 454,600 University of Nottingham students, exposing passport numbers, disability data, and credit card details.
Cybersecurity
FBI Seizes 13 Chinese Spy Sites Targeting U.S. Clearance Holders
Andrew Doyle
June 11, 2026
The FBI and DOJ seized 13 websites used by Chinese intelligence services to recruit current and former U.S. government workers who hold security clearances.
Cybersecurity
China-Linked JDY Botnet Hits 1,500 Devices Targeting U.S. Military
Mitchell Langley
June 11, 2026
Black Lotus Labs tracked the JDY botnet's growth to 1,500-plus compromised devices, with U.S. military networks identified as the primary target sector.
CVE Vulnerability Alerts
CISA BOD 26-04 Mandates 3-Day Patch Window for Federal Agencies
Gabby Lee
June 11, 2026
CISA BOD 26-04 requires all federal civilian agencies to patch critical KEV-listed exploited vulnerabilities within three days, cutting the two-week timeline.
Cybersecurity
RoguePlanet Zero-Day Gives Attackers SYSTEM on Patched Windows
Andrew Doyle
June 11, 2026
Security researcher Nightmare Eclipse dropped RoguePlanet, an unpatched LPE zero-day in Microsoft Defender that grants SYSTEM on fully patched Windows.
CVE Vulnerability Alerts
Ivanti Sentry CVE-2026-10520 Actively Exploited, Devices Backdoored
Gabby Lee
June 11, 2026
Ivanti Sentry CVE-2026-10520 is a CVSS 10.0 unauthenticated root RCE under active exploitation. Two instances were confirmed backdoored on disclosure day.
Application Security
Langflow CVE-2026-5027: Path Traversal Becomes Unauthenticated RCE
Mitchell Langley
June 11, 2026
CVE-2026-5027 in Langflow allows unauthenticated attackers to write arbitrary files via path traversal, achieving RCE on 7,000 publicly exposed AI instances.
Cybersecurity
WorldLeaks Claims Apple Supplier Tata Electronics and Two More Firms
Gabby Lee
June 11, 2026
WorldLeaks, the rebranded Hunters International group, posted three new victims: Tata Electronics, First Federal Savings & Loan, and India's Reliance Group.
Blog
What is Cloud Detection and Response (CDR) and How Does it Work
Mitchell Langley
June 10, 2026
Cloud detection and response (CDR) delivers real-time threat visibility across cloud workloads. Learn how CDR works and how to implement it.
Application Security
Google Patches 5th Chrome Zero-Day; V8 Flaw Chains for OS Access
Mitchell Langley
June 10, 2026
Google patched CVE-2026-11645, a V8 out-of-bounds flaw being chained with a sandbox escape to achieve OS code execution. The fifth Chrome zero-day of 2026.
Application Security
LiteLLM CVE-2026-42271 Added to CISA KEV: AI API Keys at Risk
Gabby Lee
June 10, 2026
CISA added BerriAI LiteLLM CVE-2026-42271 to the KEV catalog. The command injection flaw enables OS access and theft of all configured AI provider API keys.
Cybersecurity
France’s Tchap Messaging App Breached, 643K Messages Exposed
Gabby Lee
June 10, 2026
ANSSI detected attackers who used a hijacked account and hardcoded LDAP credentials to breach Tchap, exposing 643,000 messages across 73,000 accounts.
Application Security
SAP Patches CVSS 9.9 SAML Flaw and ABAP Memory Corruption
Andrew Doyle
June 10, 2026
SAP's June 2026 Patch Day addressed 15 security notes including CVE-2026-44748, a CVSS 9.9 XML Signature Wrapping flaw in NetWeaver SAML authentication.
CVE Vulnerability Alerts
Exploit Published for Linux Kernel nf_tables CVE-2026-23111
Gabby Lee
June 10, 2026
Exodus Intelligence released a working exploit for Linux kernel CVE-2026-23111, a nf_tables flaw enabling root escalation on unpatched Ubuntu and Debian.
Cybersecurity
Qilin Ransomware Hits Isuzu Motors, Opéra Comique, and 3 Others
Andrew Doyle
June 10, 2026
Qilin ransomware posted six victims including Isuzu Motors, Opéra Comique, and Australian healthcare provider The Banyans in a cross-sector June 8 batch.
Cybersecurity
Nova, Stormous, and Akira Target European Organizations
Andrew Doyle
June 10, 2026
Nova claimed Trevi S.p.A., Stormous listed a Dutch Catholic group, and Akira hit a French ambulatory clinic in coordinated European ransomware postings.
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Mitchell Langley
September 9, 2026
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
Andrew Doyle
September 11, 2026
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
TOP CYBERSECURITY HEADLINES
Application Security
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Application Security
Attackers Use BYOD Weaknesses to Access M365 via Graph API
This Week’s Security Spotlight
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Mitchell Langley
September 8, 2026
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Gabby Lee
September 1, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Oracle PeopleSoft CVE-2026-35273: ShinyHunters Breaches 100+ Orgs
June 11, 2026
Oracle issued emergency mitigations for CVE-2026-35273, an RCE flaw in PeopleSoft, after ShinyHunters breached 300 instances across more than 100 organizations.
Nottingham University Breach Exposes Data on 454,600 Students
June 11, 2026
ShinyHunters posted 40GB of stolen data on 454,600 University of Nottingham students, exposing passport numbers, disability data, and credit card details.
FBI Seizes 13 Chinese Spy Sites Targeting U.S. Clearance Holders
June 11, 2026
The FBI and DOJ seized 13 websites used by Chinese intelligence services to recruit current and former U.S. government workers who hold security clearances.
China-Linked JDY Botnet Hits 1,500 Devices Targeting U.S. Military
June 11, 2026
Black Lotus Labs tracked the JDY botnet's growth to 1,500-plus compromised devices, with U.S. military networks identified as the primary target sector.
CISA BOD 26-04 Mandates 3-Day Patch Window for Federal Agencies
June 11, 2026
CISA BOD 26-04 requires all federal civilian agencies to patch critical KEV-listed exploited vulnerabilities within three days, cutting the two-week timeline.
RoguePlanet Zero-Day Gives Attackers SYSTEM on Patched Windows
June 11, 2026
Security researcher Nightmare Eclipse dropped RoguePlanet, an unpatched LPE zero-day in Microsoft Defender that grants SYSTEM on fully patched Windows.
Ivanti Sentry CVE-2026-10520 Actively Exploited, Devices Backdoored
June 11, 2026
Ivanti Sentry CVE-2026-10520 is a CVSS 10.0 unauthenticated root RCE under active exploitation. Two instances were confirmed backdoored on disclosure day.
Langflow CVE-2026-5027: Path Traversal Becomes Unauthenticated RCE
June 11, 2026
CVE-2026-5027 in Langflow allows unauthenticated attackers to write arbitrary files via path traversal, achieving RCE on 7,000 publicly exposed AI instances.
WorldLeaks Claims Apple Supplier Tata Electronics and Two More Firms
June 11, 2026
WorldLeaks, the rebranded Hunters International group, posted three new victims: Tata Electronics, First Federal Savings & Loan, and India's Reliance Group.
What is Cloud Detection and Response (CDR) and How Does it Work
June 10, 2026
Cloud detection and response (CDR) delivers real-time threat visibility across cloud workloads. Learn how CDR works and how to implement it.
Google Patches 5th Chrome Zero-Day; V8 Flaw Chains for OS Access
June 10, 2026
Google patched CVE-2026-11645, a V8 out-of-bounds flaw being chained with a sandbox escape to achieve OS code execution. The fifth Chrome zero-day of 2026.
LiteLLM CVE-2026-42271 Added to CISA KEV: AI API Keys at Risk
June 10, 2026
CISA added BerriAI LiteLLM CVE-2026-42271 to the KEV catalog. The command injection flaw enables OS access and theft of all configured AI provider API keys.
France’s Tchap Messaging App Breached, 643K Messages Exposed
June 10, 2026
ANSSI detected attackers who used a hijacked account and hardcoded LDAP credentials to breach Tchap, exposing 643,000 messages across 73,000 accounts.
SAP Patches CVSS 9.9 SAML Flaw and ABAP Memory Corruption
June 10, 2026
SAP's June 2026 Patch Day addressed 15 security notes including CVE-2026-44748, a CVSS 9.9 XML Signature Wrapping flaw in NetWeaver SAML authentication.
Exploit Published for Linux Kernel nf_tables CVE-2026-23111
June 10, 2026
Exodus Intelligence released a working exploit for Linux kernel CVE-2026-23111, a nf_tables flaw enabling root escalation on unpatched Ubuntu and Debian.
Qilin Ransomware Hits Isuzu Motors, Opéra Comique, and 3 Others
June 10, 2026
Qilin ransomware posted six victims including Isuzu Motors, Opéra Comique, and Australian healthcare provider The Banyans in a cross-sector June 8 batch.
Nova, Stormous, and Akira Target European Organizations
June 10, 2026
Nova claimed Trevi S.p.A., Stormous listed a Dutch Catholic group, and Akira hit a French ambulatory clinic in coordinated European ransomware postings.
Turkish Police Detain 357 in Nationwide Cybercrime Raids
June 10, 2026
Turkish police detained 357 and arrested 194 in raids across 18 provinces targeting online gambling, financial fraud, and child sexual abuse material.
Apache HTTP Server 2.4.68 Patches 13 CVEs Including HTTP/2 DoS
June 10, 2026
Apache HTTP Server 2.4.68 patches 13 vulnerabilities including CVE-2026-49975, the HTTP/2 bomb denial-of-service flaw affecting nginx, Envoy, and Cloudflare.
Storm-3075 Uses ChatGPT and Claude Brands to Harvest Credentials
June 10, 2026
Microsoft identified Storm-3075 using ChatGPT, Claude, and DeepSeek brands in AiTM phishing that targeted over 2,000 organizations across the US, UK, and India.





































