NAVANEM

Security news & tech updates for sysadmins and IT pros

Cybersecurity advisories, CVE watch and the tech worth sharing, scored by trend and updated regularly, written for people who actually run infrastructure.

71stories
hourlyupdated
8sources

71 results

SimpleHelp auth bypass and credential theft.
[Vulnerabilities] · Jun 29, 2026 · 23:38 UTC

Djinn Stealer Exploits SimpleHelp CVE-2026-48558

~14,000 exposed SimpleHelp servers face Djinn Stealer via CVE-2026-48558, a CVSS 10.0 auth bypass harvesting AI, cloud, and SSH credentials across Windows, macOS, and Linux.

emanuel de almeida · read →
iOS 26.5.2 security patch illustration.
[Security] · Jun 29, 2026 · 23:27 UTC

iOS 26.5.2: Apple Rushes Patches Ahead of AI Exploit Surge

iOS 26.5.2 landed June 29, 2026, fixing 25+ CVEs pulled from the iOS 26.6 beta to outpace AI-assisted zero-day development before exploitation begins.

emanuel de almeida · read →
Illustration of CVE-2026-48558 in SimpleHelp enabling Djinn Stealer to steal credentials across Windows, macOS, and Linux.
[Vulnerabilities] · Jun 29, 2026 · 19:56 UTC

CVE-2026-48558: SimpleHelp Exploited to Drop Djinn Stealer

CVE-2026-48558 (CVSS 10.0) in SimpleHelp ≤5.5.15 is actively exploited to drop Djinn Stealer. ~1,000 servers exposed. Patch to v5.5.16 or v6.0 RC2 now.

emanuel de almeida · read →
Illustration of Mastercard’s pan-African cybersecurity hub linking South Africa and Nigeria to 50 organizations with threat intelligence.
[Tech] · Jun 29, 2026 · 16:00 UTC

Africa Cybersecurity Center of Excellence: Mastercard 2026

Mastercard's pan-African cybersecurity hub launches in South Africa and Nigeria, covering 50 organisations with Recorded Future threat intel - backed by $12.6 bn invested since 2018.

emanuel de almeida · read →
Illustration of a shared email platform breach exposing 14.22 million logins across six Japanese ISPs.
[Security] · Jun 28, 2026 · 15:26 UTC

KDDI Data Breach: 14.22 Million Email Logins Exposed

KDDI data breach exposed 14.22 million email logins across six Japanese ISPs after attackers exploited a third-party software flaw in a shared email platform.

emanuel de almeida · read →
Illustration of a Python exploit for CVE-2026-31431 escalating privileges on Linux servers with a patching warning.
[Vulnerabilities] · Jun 28, 2026 · 12:15 UTC

CVE-2026-31431 Copy Fail: Linux Privilege Escalation Flaw

A 732-byte Python script exploits CVE-2026-31431 (CVSS 7.8) to grant root on Ubuntu, RHEL, and Amazon Linux. CISA mandates federal patching by May 15, 2026.

emanuel de almeida · read →
Illustration of malware hidden in a legitimate GitHub repository being triggered by an AI coding agent after cloning.
[Security] · Jun 27, 2026 · 15:17 UTC

Miasma Worm Hijacks AI Coding Agents via GitHub Repos

448 artifacts poisoned: the Miasma worm plants malware in clean GitHub repos that fires automatically when AI coding agents clone them, evading every standard scanner.

emanuel de almeida · read →
Illustration of a large-scale fraud campaign with hundreds of thousands of malicious domains built on a mobile app platform and impacting many enterprises.
[Security] · Jun 27, 2026 · 13:13 UTC

DCloud Uni-App Powers 236,000 Global Investment Scam Sites

985 enterprises hit: Infoblox found 236,493 fraudulent domains built on DCloud Uni-App since 2022, spiking to 15,000 new scam sites per month after October 2024 disclosure.

emanuel de almeida · read →
Illustration of a critical SSRF vulnerability in Cisco Unified CM under active exploitation with urgent patching required.
[Vulnerabilities] · Jun 27, 2026 · 01:18 UTC

Cisco Unified CM SSRF Flaw CVE-2026-20230: Patch by June 28

CISA added CVE-2026-20230, a CVSS 8.6 SSRF flaw in Cisco Unified CM, to its KEV catalog June 25, 2026. Federal agencies must patch by June 28, 2026.

emanuel de almeida · read →
Illustration of a restricted AI model rollout limited to a small group of approved partners during a federal cybersecurity review.
[Security] · Jun 26, 2026 · 23:59 UTC

GPT-5.6 Sol Restricted: OpenAI Pauses Launch for Federal Review

OpenAI limits GPT-5.6 Sol to roughly 20 Trump-approved partners while a 30-day federal cybersecurity review under a June 2, 2026 executive order runs its course.

emanuel de almeida · read →
Illustration of an actively exploited critical Splunk Enterprise pre-auth remote code execution vulnerability.
[Vulnerabilities] · Jun 26, 2026 · 21:18 UTC

CVE-2026-20253: Critical Splunk RCE Actively Exploited

A CVSS 9.8 pre-auth RCE flaw in Splunk Enterprise is under active attack. CISA added it to KEV on June 18. Over 1,400 instances exposed. Patch by June 21.

emanuel de almeida · read →
Illustration of a Turla backdoor campaign targeting Ukrainian government and military networks through a WinRAR vulnerability.
[Security] · Jun 26, 2026 · 13:19 UTC

STOCKSTAY Backdoor: Turla Targets Ukraine with .NET Espionage Tool

Turla's STOCKSTAY .NET backdoor has hit Ukrainian government and military networks since December 2022, exploiting WinRAR flaw CVE-2023-38831 flagged by CISA.

emanuel de almeida · read →
Illustration of a critical Windchill and FlexPLM remote code execution vulnerability added to a known exploited vulnerabilities catalog after active exploitation.
[Vulnerabilities] · Jun 26, 2026 · 09:14 UTC

CVE-2026-12569: PTC Windchill RCE Exploited, CISA Warns

CISA added CVE-2026-12569 to its KEV catalog on June 25, 2026. The critical Windchill RCE flaw scores 9.3 CVSS v4.0 and requires no authentication to exploit.

emanuel de almeida · read →
Illustration of a mobile AI task dashboard showing Claude Cowork-style long-running tasks being started and monitored from a phone.
[Tech] · Jun 26, 2026 · 01:20 UTC

Claude Cowork Mobile Testing: What Paid Users Need to Know

Anthropic is testing mobile support for Claude Cowork, letting Pro and Max users start and monitor long-running AI tasks from their phones. GA launched April 9, 2026.

emanuel de almeida · read →
Illustration of a self-deleting backdoor linked to an access broker and multiple ransomware groups
[Security] · Jun 25, 2026 · 22:50 UTC

Mistic Backdoor: KongTuke Access Broker Fuels Ransomware

Symantec confirmed June 24, 2026 that the fileless Mistic backdoor links to KongTuke, an access broker selling footholds to six ransomware groups since May 2024.

emanuel de almeida · read →
Illustration of a fake purchase receipt scam used to lure users into calling a fraudulent support line
[Security] · Jun 25, 2026 · 21:49 UTC

Callback Phishing via Shop App: Fake Receipts Target 875M Users

Callback phishing grew 500% in Q4 2025 as attackers plant fake receipts in Shopify's Shop app, tricking 875M+ consumers into calling fraudulent support lines.

emanuel de almeida · read →
Illustration of Microsoft extending free consumer ESU support to a later end date for Windows devices
[Tech] · Jun 25, 2026 · 20:03 UTC

Windows 10 ESU Extended Free to October 2027: What Changed

Microsoft quietly moved the free consumer Windows 10 ESU deadline to October 12, 2027. Free enrollment, $30 for 10 devices, or 1,000 Rewards points.

emanuel de almeida · read →
Illustration of a fileless backdoor attack used by KongTuke against insurance, education, and IT organizations
[Security] · Jun 25, 2026 · 17:49 UTC

Mistic Backdoor Tied to KongTuke Ransomware Broker

Symantec and Zscaler documented Mistic, a fileless backdoor used by KongTuke IAB since April 2026, targeting insurance, education, IT, and professional services firms.

emanuel de almeida · read →
Illustration of a Cisco Catalyst SD-WAN command injection flaw exploited before disclosure and patching
[Vulnerabilities] · Jun 25, 2026 · 17:33 UTC

CVE-2026-20245: Cisco SD-WAN Zero-Day Exploited Months Before Patch

March 2026: attackers exploited CVE-2026-20245 in Cisco Catalyst SD-WAN months before Cisco's June 5 disclosure. CISA added it to KEV on June 9, 2026.

emanuel de almeida · read →
Illustration of Chrome 149 patching 18 security flaws including four critical use-after-free bugs
[Vulnerabilities] · Jun 25, 2026 · 08:58 UTC

Chrome 149 Patches 18 Vulnerabilities, Four Rated Critical

Chrome 149.0.7827.196/197 fixes 18 flaws - 4 Critical UAF bugs in WebGL. CVE-2026-11645 actively exploited, CISA KEV listed, federal deadline June 23, 2026.

emanuel de almeida · read →
show