Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

16/06/2026 0 Comments 0 tags

Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

16/06/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB)

Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

16/06/2026 0 Comments 0 tags

Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

16/06/2026 0 Comments 0 tags

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. “The attack email

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

15/06/2026 0 Comments 0 tags

A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was

North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels

15/06/2026 0 Comments 0 tags

Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

15/06/2026 0 Comments 0 tags

A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

15/06/2026 0 Comments 0 tags

A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis

⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

15/06/2026 0 Comments 0 tags

Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

15/06/2026 0 Comments 0 tags

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site