2026-06-19 06:41 UTC
Vendor Research
Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-15 18:55 UTC
Gogs - Authentication Bypass via Unvalidated Reverse Proxy Headers When 'ENABLE_REVERSE_PROXY_AUTHENTICATION' is enabled, Gogs accepts the configured authentication header (default: 'X-WEBAUTH-USER') directly from client requests without validating that the request originated from a trusted reverse proxy.Any remote attacker who can reach the Gogs service can forge this header to impersonate any user or trigger automatic account creation, completely bypassing authentication. Joshua Martinelle Fr…
P10
2026-06-18 17:59 UTC
Vendor Research
Cloudflare Security · Dan Jones · indexed 2026-08-15 18:58 UTC
We break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.
P0
2026-06-18 09:46 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
P0
2026-06-18 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress was one of many vendors impacted by a recent incident at Klue. We dug into the incident to figure out what happened.
P0
2026-06-18 05:23 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-15 18:55 UTC
Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates.Key TakeawaysThe June 2026 Critical Security Patch Update (CSPU) contains fixes for 243 unique CVEs in 245 security updates122 issues (49.8% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 106, accounting for 43.3% of all patchesBackgroundOn June 16, Oracle released its Critical Security Patch Update…
P65
2026-06-18 04:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Se ha descubierto una infraestructura de phishing modular dirigida a múltiples bancos mexicanos, que abusa de GitHub Pages, emplea scripts ofuscados y centraliza la exfiltración de credenciales mediante la API de SheetBest, lo que indica una operación de phishing escalable y persistente de múltiples marcas.
P0
2026-06-17 16:09 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution A .NET deserialization vulnerability exists in iba ibaPDA, ibaDatCoordinator and ibaLogic. An unauthenticated remote attacker can exploit it to achieve remote code execution.The ibaPDA Server service (ibaPDAService.exe) listens on TCP port 9170 by default. Clients communicate with the server using GenuineChannels, which uses .NET Remoting. Messages sent to the server are deserialized using BinaryFormatter. GenuineChannels…
P15
2026-06-17 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root. Cisco has released software updates that address this vulnerability. There…
P15
2026-06-17 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in the configuration template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands…
P5
2026-06-17 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to click a crafted URL. A…
P5
2026-06-17 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed ISPM finds and closes Microsoft 365 identity gaps before attackers do. Learn why visibility isn't enough and what real identity hardening takes.
P0
2026-06-17 08:45 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.
P0
2026-06-17 06:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation.
P0
2026-06-16 17:39 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit…
P15
2026-06-16 17:39 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The Indicators of Compromise section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco …
P15
2026-06-16 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A ClickFix infection drops Potemkin loader and RMMProject RAT, leading to browser theft, hidden remote desktop, and lateral movement across over 11 hosts.
P0
2026-06-16 08:54 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness
P0
2026-06-15 22:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit…
P5
2026-06-15 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A compromised terminal server became a phishing stager. A fake Boots survey aimed at 8.9 million inboxes, with the payload on a hacked Bolivian government site.
P0
2026-06-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abuse…
P0
2026-06-15 08:55 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
P0
2026-06-12 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A recent investigation uncovered an Akira affiliate abusing a website owned by file-sharing app LimeWire for data exfiltration. Here's how the attack unfolded.
P0
2026-06-11 18:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress traced device code phishing from Tencent Cloud to Kali365, a Microsoft 365 kit that steals tokens and keeps access even after MFA or password resets.
P0
2026-06-11 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns wi…
P45
2026-06-11 08:45 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A shift in operational pattern of the infamous Vietnam-aligned APT group
P0
2026-06-11 07:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog provides a deep-dive into SniperDz, a centralised PhaaS platform with more than 80 ready-made phishing templates impersonating over 30 global brands, and uncovers the hidden infrastructure behind this sophisticated and highly-organized fraud ecosystem.
P0
2026-06-10 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Deceptive installers disguised as legit macOS software deliver infostealers that grab passwords, cookies, and crypto wallets. Learn how to detect them.
P0
2026-06-10 11:55 UTC
Government
CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
P15
2026-06-10 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A company that's expecting a cyberattack but hasn’t actively prepared for it risks making the hardest decisions at the worst possible moment
P0
2026-06-10 07:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
SilabRAT (aka SnappyClient) is an advanced Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) on Darkweb forums. Developed by the threat actor "o1oo1," SilabRAT is heavily focused on financial gain through credential theft. It offers stability and is capable of bypassing existing security measures.
P0