PublicCVE

Newsroom

CISA warns of max severity Ubiquiti flaws exploited in attacks
BleepingComputer · 5d ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]

Amadey, StealC malware operations disrupted in Operation Endgame action
BleepingComputer · 5d ago

Microsoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercriminal services and ransomware gangs. [...]

Securing the service desk: Why social engineering attacks keep succeeding
BleepingComputer · 5d ago

Service desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk social engineering attacks work and how organizations can defend against them. [...]

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
The Hacker News · 5d ago

Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote

News
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
BleepingComputer · 5d ago

A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors. [...]

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
The Hacker News · 5d ago

A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. "The main common goal was to disrupt the 'assembly lines' cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure," Europol said in

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
The Hacker News · 5d ago

Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "critical exploitable pattern" has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and

Dawn of the Apex Agentic Adversary
The Hacker News · 5d ago

We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or even months later, a fix was deployed. In this era, dwell time was measured in days, sometimes weeks. We are now approaching an

More Malicious OpenClaw Skills Threaten AI Supply Chain
Dark Reading · 5d ago

OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats.

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
The Hacker News · 5d ago

The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entities linked to Prince Group. "These subsidiaries are alleged to have assisted individuals and organizations in transferring proceeds of

Apple's MacOS Gap Lets Users Disable Security Tools
Dark Reading · 5d ago

Attackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits.

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
BleepingComputer · 5d ago

A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. [...]

Tata Electronics confirms cyberattack as hackers leak data
BleepingComputer · 5d ago

Tata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. [...]

Windows 11 KB5095093 update rolls out new Point-in-Time restore feature
BleepingComputer · 5d ago

​​Microsoft has released the KB5095093 preview cumulative update for Windows 11 24H2 and 25H2, which fixes numerous bugs and begins rolling out new features, including the new Point-in-Time restore feature. [...]

Healthtech firm Xolis suffers data breach impacting 1.4 million people
BleepingComputer · 5d ago

Healthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing attack that gave attackers access to its network. [...]

New macOS ClickFix attack silently mounts DMGs to push infostealer
BleepingComputer · 6d ago

A new macOS ClickFix campaign is using Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files. [...]

Scattered Spider members plead guilty to hacking Transport for London
BleepingComputer · 6d ago

Two members of the 'Scattered Spider' cybercrime group pleaded guilty to hacking the Transport for London (TfL) systems in 2024. [...]

The Exploit Doesn't Exist. You Can Still Prove It Works Against You
BleepingComputer · 6d ago

Attackers can now weaponize newly disclosed vulnerabilities far faster than most organizations can patch them. Picus Security explains how security teams can validate exploitability before a public exploit even exists. [...]

LastPass confirms data breach in Klue supply chain attack
BleepingComputer · 6d ago

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. [...]

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
The Hacker News · 6d ago

A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespoke

Webinar: Why email security teams are drowning in alerts
BleepingComputer · 6d ago

Phishing, BEC, and account takeover attacks continue to overwhelm security teams with alerts and investigations. This webinar explores how behavioral AI can help automate detection and response workflows, reducing alert fatigue and improving operational efficiency. [...]

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
The Hacker News · 6d ago

Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user's email address and did nothing else. The point was to show

Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration
The Hacker News · 6d ago

President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography. Key establishment must move by December 31, 2030; digital signatures by December 31, 2031. EO 14409 leaves national security systems on a separate track. The deadlines matter because of a threat that does not

Scope of Salesforce Attacks Expands as Icarus Leaks Data
Dark Reading · 5d ago

More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.

GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
The Hacker News · 6d ago

GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code with the workflow's full privileges. Effective June 18, 2026, the latest version of "actions/checkout," the official GitHub action for checking out a repository into the

'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
Dark Reading · 5d ago

The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK, and Python Software Foundation's Black.

Agentic AI: The Weapon That No Longer Needs a Warrior
The Hacker News · 6d ago

Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's death a quarter mile beyond his sight, and the aircraft carried that death across oceans. At each turn, the distance between the warrior and the wound grew wider, and yet one thing never moved: a human chose the target

Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
The Hacker News · 6d ago

Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT). The list of identified packages, is below - aes-decode-runner-pro (145 downloads) postcss-minify-selector (256 downloads) postcss-minify-selector-parser (615 downloads) All the packages were published over the past month by an npm user named

SocGholish Takedown Highlights Malicious TDS Threats
Dark Reading · 6d ago

SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious Evil Corp.

FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
Dark Reading · 6d ago

The threat actors engineered a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign.