NAVANEM

Security news & tech updates for sysadmins and IT pros

Cybersecurity advisories, CVE watch and the tech worth sharing, scored by trend and updated regularly, written for people who actually run infrastructure.

16stories
hourlyupdated
8sources

16 results

AI policy themed image showing Anthropic’s top models restricted for foreign users and security executives calling for the ban to be lifted
[Security] · Jun 15, 2026 · 20:19 UTC

Anthropic Export Ban: 76 Security Execs Demand Reversal

76 cybersecurity executives from Adobe, Google, Nvidia signed an open letter urging Commerce to lift Anthropic Fable 5 and Mythos 5 export controls.

emanuel de almeida · read →
Visualization of an active exploit targeting a critical Cisco SD-WAN vulnerability
[Vulnerabilities] · Jun 15, 2026 · 17:55 UTC

CVE-2026-20262: Cisco SD-WAN Root Bug Actively Exploited

Cisco patches CVE-2026-20262, a critical Catalyst SD-WAN Manager flaw granting root access. CISA issued Emergency Directive 26-03 as UAT-8616 exploits systems.

emanuel de almeida · read →
Microsoft 365 Copilot interface being abused via malicious URLs to steal sensitive data
[Vulnerabilities] · Jun 15, 2026 · 15:27 UTC

SearchLeak Vulnerability in Microsoft 365 Copilot Enables One-Click Data Theft

CVE-2026-42824 chains three flaws to exfiltrate emails, passwords, and documents via malicious URLs. Microsoft has patched server-side.

emanuel de almeida · read →
Illustration of Conti ransomware developer Oleksii Lytvynenko pleading guilty and facing up to 20 years in prison
[Security] · Jun 15, 2026 · 13:53 UTC

Conti Ransomware Developer Pleads Guilty: Ukrainian Faces 20 Years in Prison

Oleksii Lytvynenko admitted to building malware loaders for Conti, which extorted over $150 million from victims across 47 U.S. states and 31 countries.

emanuel de almeida · read →
Windows 11 KB5094126 June 2026 Patch Tuesday cover
[Tech] · Jun 13, 2026 · 21:13 UTC

Windows 11 KB5094126 June 2026: Key Fixes for Sysadmins

KB5094126 fixes HYPERVISOR_ERROR 0x20001 crashes and BitLocker recovery loops. Released June 9, 2026 for Windows 11 24H2/25H2.

emanuel de almeida · read →
npm 12 blocks install scripts by default to combat supply chain attacks - navanem news cover
[Security] · Jun 13, 2026 · 19:24 UTC

npm 12 Blocks Install Scripts by Default: July 2026 Deadline

npm v12 disables dependency install scripts starting July 2026, affecting 2M+ packages. Developers must whitelist trusted packages via allowScripts in package.json.

emanuel de almeida · read →
June 2026 Patch Tuesday: 206 CVEs and 3 zero-days fixed - cover
[Security] · Jun 12, 2026 · 22:00 UTC

June 2026 Patch Tuesday: 3 Zero-Days, 206 CVEs Fixed

Microsoft's largest-ever Patch Tuesday fixes 206 CVEs including three actively exploited zero-days. BitLocker bypass, Defender privilege escalation actively exploited.

emanuel de almeida · read →
Oracle PeopleSoft zero-day exploited by ShinyHunters - cover art
[Vulnerabilities] · Jun 12, 2026 · 19:54 UTC

CVE-2026-35273: Oracle PeopleSoft Zero-Day Exploited

CVE-2026-35273 enables unauthenticated RCE in Oracle PeopleSoft. ShinyHunter exploits this zero-day to steal HR/payroll data. Emergency patch available.

emanuel de almeida · read →
Exchange Server zero-day exploited against OWA users - cover art
[Vulnerabilities] · Jun 12, 2026 · 15:45 UTC

Exchange Server Zero-Day CVE-2024-21413 Patched

Microsoft patches CVE-2024-21413 Exchange Server zero-day exploited against OWA users. Over 97,000 servers vulnerable. XSS flaw allows JavaScript injection. Patch now.

emanuel de almeida · read →
Windows Server 2025 June 2026 update KB5094125: DoH, BitLocker and Secure Boot fixes
[Tech] · Jun 12, 2026 · 12:00 UTC

Windows Server 2025 June Update KB5094125: DoH, BitLocker Fix

KB5094125 adds DNS over HTTPS support, fixes April's BitLocker recovery bug, and includes Secure Boot certificate controls for Windows Server 2025.

emanuel de almeida · read →
Microsoft Patch Tuesday record 200 CVEs - cover
[Vulnerabilities] · Jun 11, 2026 · 17:00 UTC

Patch Tuesday June 2024: Microsoft Fixes 51 Flaws, One Zero-Day

Microsoft's June 2024 Patch Tuesday addresses 51 vulnerabilities including 18 RCE flaws. CVE-2024-30080 MSMQ bug scores 9.8 CVSS and demands immediate patching.

emanuel de almeida · read →
Windows Server 2016 Secure Boot privacy update KB5094122
[Security] · Jun 11, 2026 · 12:00 UTC

KB5094122: Windows Server 2016 Secure Boot Privacy Update

KB5094122 brings build 14393.9234 to Windows Server 2016 with Secure Boot telemetry controls, a DFS namespace fix, and desktop.ini hardening.

emanuel de almeida · read →
Microsoft Defender RoguePlanet zero-day grants SYSTEM privileges on patched Windows
[Vulnerabilities] · Jun 10, 2026 · 12:00 UTC

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Privileges on Patched Systems

New RoguePlanet exploit bypasses June 2026 patches to spawn SYSTEM-level prompts via Defender race condition. Seventh release from Nightmare Eclipse in ten weeks.

emanuel de almeida · read →
Chrome zero-day exploited then patched - cover
[Vulnerabilities] · Jun 10, 2026 · 06:00 UTC

Chrome Zero-Day CVE-2026-11645 Patched: Update Now

Google patches CVE-2026-11645, Chrome's fifth zero-day of 2026. With 3.83 billion users at risk, CISA mandates federal remediation by June 23.

emanuel de almeida · read →
Cracked Check Point VPN shield with keyhole - Qilin ransomware zero-day cover art
[Security] · Jun 10, 2026 · 04:24 UTC

Check Point VPN Zero-Day Exploited by Qilin Ransomware

CVE-2026-50751 lets Qilin ransomware bypass Check Point VPN authentication. CISA mandates a 72-hour patch deadline. Learn detection steps and fixes.

emanuel de almeida · read →
ServiceNow unauthenticated API flaw exposed customer data - cover
[Security] · Jun 9, 2026 · 12:00 UTC

ServiceNow API Flaw Exposes Customer Data: Response Guide

A ServiceNow API flaw exposed customer data from June 2-3, 2026. ServiceNow patched the unauthenticated endpoint on June 5. Here's what 8,700+ customers must do now.

emanuel de almeida · read →