ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories

11/06/2026 0 Comments 0 tags

It’s been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there’s a supply chain attack kit in a public

Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories

11/06/2026 0 Comments 0 tags

Most good security work is invisible by design. Today is the exception. The 2026 Cybersecurity Stars Awards winners are announced across 95 subcategories in four main award categories. The reason

AI Broke Vulnerability Management. That’s Why CISOs Are Moving Budget to BAS.

11/06/2026 0 Comments 0 tags

For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponize it. The solution was

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack

11/06/2026 0 Comments 0 tags

The Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and stock investors with a backdoor known as SPECTRALVIPER. The campaigns involve

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

11/06/2026 0 Comments 0 tags

GitHub has announced what it said are “breaking changes” coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The

CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation

10/06/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The list of vulnerabilities

Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

10/06/2026 0 Comments 0 tags

A high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck.

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

10/06/2026 0 Comments 0 tags

Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

10/06/2026 0 Comments 0 tags

Cybersecurity researchers have warned of a “resurgence and expansion” of JDY, a covert network associated with China-nexus state-sponsored threat actors. “The JDY botnet comprises over 1,500 SOHO [small office and

Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs

10/06/2026 0 Comments 0 tags

Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that have been publicly disclosed at the time of release. Of the