Security news & tech updates for sysadmins and IT pros
Cybersecurity advisories, CVE watch and the tech worth sharing, scored by trend and updated regularly, written for people who actually run infrastructure.
71 results

Djinn Stealer Exploits SimpleHelp CVE-2026-48558
~14,000 exposed SimpleHelp servers face Djinn Stealer via CVE-2026-48558, a CVSS 10.0 auth bypass harvesting AI, cloud, and SSH credentials across Windows, macOS, and Linux.

iOS 26.5.2: Apple Rushes Patches Ahead of AI Exploit Surge
iOS 26.5.2 landed June 29, 2026, fixing 25+ CVEs pulled from the iOS 26.6 beta to outpace AI-assisted zero-day development before exploitation begins.

CVE-2026-48558: SimpleHelp Exploited to Drop Djinn Stealer
CVE-2026-48558 (CVSS 10.0) in SimpleHelp ≤5.5.15 is actively exploited to drop Djinn Stealer. ~1,000 servers exposed. Patch to v5.5.16 or v6.0 RC2 now.

Africa Cybersecurity Center of Excellence: Mastercard 2026
Mastercard's pan-African cybersecurity hub launches in South Africa and Nigeria, covering 50 organisations with Recorded Future threat intel - backed by $12.6 bn invested since 2018.

KDDI Data Breach: 14.22 Million Email Logins Exposed
KDDI data breach exposed 14.22 million email logins across six Japanese ISPs after attackers exploited a third-party software flaw in a shared email platform.

CVE-2026-31431 Copy Fail: Linux Privilege Escalation Flaw
A 732-byte Python script exploits CVE-2026-31431 (CVSS 7.8) to grant root on Ubuntu, RHEL, and Amazon Linux. CISA mandates federal patching by May 15, 2026.

Miasma Worm Hijacks AI Coding Agents via GitHub Repos
448 artifacts poisoned: the Miasma worm plants malware in clean GitHub repos that fires automatically when AI coding agents clone them, evading every standard scanner.

DCloud Uni-App Powers 236,000 Global Investment Scam Sites
985 enterprises hit: Infoblox found 236,493 fraudulent domains built on DCloud Uni-App since 2022, spiking to 15,000 new scam sites per month after October 2024 disclosure.

Cisco Unified CM SSRF Flaw CVE-2026-20230: Patch by June 28
CISA added CVE-2026-20230, a CVSS 8.6 SSRF flaw in Cisco Unified CM, to its KEV catalog June 25, 2026. Federal agencies must patch by June 28, 2026.

GPT-5.6 Sol Restricted: OpenAI Pauses Launch for Federal Review
OpenAI limits GPT-5.6 Sol to roughly 20 Trump-approved partners while a 30-day federal cybersecurity review under a June 2, 2026 executive order runs its course.

CVE-2026-20253: Critical Splunk RCE Actively Exploited
A CVSS 9.8 pre-auth RCE flaw in Splunk Enterprise is under active attack. CISA added it to KEV on June 18. Over 1,400 instances exposed. Patch by June 21.

STOCKSTAY Backdoor: Turla Targets Ukraine with .NET Espionage Tool
Turla's STOCKSTAY .NET backdoor has hit Ukrainian government and military networks since December 2022, exploiting WinRAR flaw CVE-2023-38831 flagged by CISA.

CVE-2026-12569: PTC Windchill RCE Exploited, CISA Warns
CISA added CVE-2026-12569 to its KEV catalog on June 25, 2026. The critical Windchill RCE flaw scores 9.3 CVSS v4.0 and requires no authentication to exploit.

Claude Cowork Mobile Testing: What Paid Users Need to Know
Anthropic is testing mobile support for Claude Cowork, letting Pro and Max users start and monitor long-running AI tasks from their phones. GA launched April 9, 2026.

Mistic Backdoor: KongTuke Access Broker Fuels Ransomware
Symantec confirmed June 24, 2026 that the fileless Mistic backdoor links to KongTuke, an access broker selling footholds to six ransomware groups since May 2024.

Callback Phishing via Shop App: Fake Receipts Target 875M Users
Callback phishing grew 500% in Q4 2025 as attackers plant fake receipts in Shopify's Shop app, tricking 875M+ consumers into calling fraudulent support lines.

Windows 10 ESU Extended Free to October 2027: What Changed
Microsoft quietly moved the free consumer Windows 10 ESU deadline to October 12, 2027. Free enrollment, $30 for 10 devices, or 1,000 Rewards points.

Mistic Backdoor Tied to KongTuke Ransomware Broker
Symantec and Zscaler documented Mistic, a fileless backdoor used by KongTuke IAB since April 2026, targeting insurance, education, IT, and professional services firms.

CVE-2026-20245: Cisco SD-WAN Zero-Day Exploited Months Before Patch
March 2026: attackers exploited CVE-2026-20245 in Cisco Catalyst SD-WAN months before Cisco's June 5 disclosure. CISA added it to KEV on June 9, 2026.

Chrome 149 Patches 18 Vulnerabilities, Four Rated Critical
Chrome 149.0.7827.196/197 fixes 18 flaws - 4 Critical UAF bugs in WebGL. CVE-2026-11645 actively exploited, CISA KEV listed, federal deadline June 23, 2026.