> TODAY'S SUMMARY (34 articles)
Today's cybersecurity landscape highlights several critical threats and trends. A significant zero-day vulnerability (CVE-2026-88) in Citrix NetScaler has been actively exploited, prompting urgent updates for affected systems. Similarly, the Rejetto HFS flaw (CVE-2026-61500) is being targeted, allowing attackers to gain administrative access and execute remote code. In the realm of healthcare, a bipartisan bill has been passed to strengthen cybersecurity measures, following over 730 breaches affecting hundreds of millions of Americans last year. On the AI front, Google has paused its open-source bug bounty program due to a surge in invalid, AI-generated vulnerability reports. Additionally, recent arrests connected to cybercrime groups like ShinyHunters signal ongoing efforts to combat organized hacking networks.
|
// AI-powered summary generated at 12:00
Meta’s WhatsApp demands contempt ruling after users report NSO Group-linked phishing
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds BerriAI LiteLLM and Check Point Security Gateway flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added BerriAI LiteLLM and Check Point Security Gateway flaws to it...
A Linux kernel nf_tables bug lets local users gain root via use-after-free caused by a logic error; patch removes a single “!”. CVE-2026-23111 lives in nf_tables, the Linux kernel’s packet filtering framework. Exodus Intelligence researcher Oliver Sieber found the bug in early 2025 and chained it in...
CVSSv3 Score:
9.1
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests....
CVSSv3 Score:
6.0
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands.
Revised on 2026-06-09 00:00:00
AI agents in your Entra ID tenant? They come with new identities, permissions, and fresh attack paths.
Christian Feuchter breaks down Entra Agent ID security, security-relevant capabilities, control paths, abuse scenarios, and how to review your exposure with EntraFalcon.
CVSSv3 Score:
6.2
An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests.
Revised on 2026-06-09 00:00:00
Google has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year. [...]
Loupe, l'application gratuite et open source pour iOS et iPadOS, révèle comment les apps tierces créent une empreinte numérique unique grâce aux API publiques.
Le post Vie privée : l’appli open source Loupe révèle le fingerprinting sur iPhone a été publié sur IT-Connect.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-42271 (CVSS score: 8.7), is a command...
Tchap, la messagerie instantanée réservée aux agents publics français a été la cible d'une intrusion suite à la compromission du compte d'un agent.
Le post Cyberattaque Tchap : un pirate s’est introduit sur la messagerie chiffrée de l’État a été publié sur IT-Connect.
In our post about Project Glasswing, we made the argument that the architecture around a vulnerability matters more than the speed of the patch. Here we walk through what that architecture looks like, the threats it defends against, and how we run it ourselves as Cloudflare's customer zero.
The advent of AI-assisted vulnerability discovery and autonomous exploit development has brought about a new age in cybersecurity—one in which we can no longer rely on patching as a primary defense mechanism. Patching is, by definition, a reactive approach to security. It cannot occur until after a...
The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher.
The post Google Patches 5th Chrome Zero-Day Exploited in 2026 appeared first on SecurityWeek.
In this interview with Help Net Security, Paras Malhotra, CISO at Starburst, explains how the company handles data governance across federated query environments. Topics include layering Starburst’s access controls above native source permissions, tiering vendor risk across more than 200 partners an...
Threat actors are continuing their onslaught against software supply chains, now with malware named after death itself.
The newly-discovered Hades Campaign is a “highly sophisticated” supply chain compromise that targets Python developer environments and runs as soon as inf...
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following C...
This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The...