NAVANEM

Security news & tech updates for sysadmins and IT pros

Cybersecurity advisories, CVE watch and the tech worth sharing, scored by trend and updated regularly, written for people who actually run infrastructure.

71stories
hourlyupdated
8sources

71 results

Illustration of a Cisco Catalyst SD-WAN Manager CLI vulnerability enabling command injection and rogue root account creation
[Vulnerabilities] · Jun 24, 2026 · 21:58 UTC

CVE-2026-20245: How Cisco SD-WAN Attackers Got Root

CVSS 7.8 zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN Manager lets authenticated attackers escalate to root - Mandiant confirms active exploitation across all deployment types.

emanuel de almeida · read →
Illustration of a malicious Edge extension escaping the browser sandbox via Native Messaging to drop a Python backdoor and ransomware-linked payload
[Security] · Jun 24, 2026 · 21:16 UTC

Edgecution Malware: Edge Extension Deploys Ransomware

Edgecution abuses Edge Native Messaging to escape the browser sandbox, drop a Python backdoor, and trigger Payouts King ransomware with 4,096-bit RSA + 256-bit AES encryption.

emanuel de almeida · read →
Illustration of five malicious ClawHub skills bypassing scanners and spreading macOS infostealers and agentic financial threats
[Security] · Jun 24, 2026 · 20:14 UTC

OpenClaw Skills Bypass AI Scanners, Hit Supply Chain

Five ClawHub skills evaded VirusTotal and ClawScan for months - part of 341 malicious entries (12% of the registry) targeting OpenClaw users with macOS infostealers.

emanuel de almeida · read →
Illustration of a global law-enforcement cyber operation seizing servers and domains and recovering millions of stolen credentials
[Security] · Jun 24, 2026 · 19:46 UTC

Operation Endgame 2026: Amadey and StealC Disrupted

Europol and partners seized 326 servers, 142 domains, and recovered 27 million credentials from 385,000+ systems in Operation Endgame's latest phase.

emanuel de almeida · read →
Illustration of a GitHub Actions supply chain attack stealing credentials and poisoning open source software
[Vulnerabilities] · Jun 24, 2026 · 18:44 UTC

Cordyceps: GitHub Actions Flaws Risk Millions of Repos

Cordyceps flaws in GitHub Actions exposed 300+ repos - including Microsoft and Google - to credential theft and supply-chain poisoning. Here is what to fix.

emanuel de almeida · read →
Illustration of unauthenticated attackers hijacking UniFi OS devices through three critical vulnerabilities flagged as high risk
[Vulnerabilities] · Jun 24, 2026 · 13:21 UTC

UniFi OS CVSS 10.0 Flaws Actively Exploited - Patch Now

Three CVSS 10.0 flaws in Ubiquiti UniFi OS let unauthenticated attackers hijack devices. CISA added them to KEV on June 23, 2026. Patch to UniFi OS 5.1.12 before the June 26, 2026 federal deadline.

emanuel de almeida · read →
Illustration of a Cisco Unified CM WebDialer SSRF attack path leading to root compromise and a mitigation branch showing patching or disabling the service
[Vulnerabilities] · Jun 23, 2026 · 22:15 UTC

Cisco Unified CM CVE-2026-20230 SSRF: Active Exploitation Reported

CVE-2026-20230, a CVSS 8.6 SSRF flaw in Cisco Unified CM, carries a Critical rating due to root privilege escalation risk. Patch to 14SU6 or disable WebDialer now. No CISA KEV listing yet.

emanuel de almeida · read →
Illustration of a Windows 11 preview update adding VSS-backed system restore while breaking Office launches from some third-party apps
[Tech] · Jun 23, 2026 · 20:56 UTC

KB5095093: Windows 11 Point-in-Time Restore & Office Bug

KB5095093 (June 23, 2026) adds VSS snapshots covering 72 hours on drives 200 GB+ and breaks OLE automation for Office on 24H2/25H2 (build 26100.8737).

emanuel de almeida · read →
Illustration of a macOS ClickFix attack where a user pastes Terminal commands that download malware from a malicious DMG file and bypass Gatekeeper
[Security] · Jun 23, 2026 · 19:48 UTC

macOS ClickFix: Terminal Commands Silently Drop Infostealers

macOS ClickFix campaigns trick users into pasting Terminal commands that silently install infostealers, bypassing Gatekeeper on managed and personal Macs alike.

emanuel de almeida · read →
Illustration of Windows 11 devices receiving a lightweight enablement-package style feature update rollout in an enterprise environment
[Tech] · Jun 23, 2026 · 17:33 UTC

Windows 11 26H2: What IT Admins Need to Know

Microsoft confirmed Windows 11 26H2 on June 19, 2026 for Fall 2026 release. Devices on 24H2 or 25H2 upgrade via a ~200 KB enablement package, not a full OS reinstall.

emanuel de almeida · read →
Illustration of a WhatsApp-delivered VBS file infecting a Windows laptop and enabling attacker remote access
[Security] · Jun 23, 2026 · 17:28 UTC

WhatsApp VBScript Malware: How Attackers Hijack Windows PCs

WhatsApp VBScript malware is actively targeting Windows PCs across 11 countries: attackers send .vbs files that hijack systems via WSH. Here is how to block it now.

emanuel de almeida · read →
Illustration of a malicious video file triggering a heap out-of-bounds write in FFmpeg's MagicYUV decoder
[Vulnerabilities] · Jun 23, 2026 · 17:13 UTC

FFmpeg CVE-2026-8461 (PixelSmash): RCE via Media Files

A heap out-of-bounds write in FFmpeg's MagicYUV decoder scores CVSS 8.8 and hits 9+ apps including Jellyfin and Nextcloud. Patch to FFmpeg 8.1.2 now.

emanuel de almeida · read →
Illustration of stolen OAuth tokens used to breach Salesforce data through a third-party app, affecting multiple organizations
[Security] · Jun 23, 2026 · 17:04 UTC

Klue OAuth Supply Chain Attack Hits LastPass Salesforce Data

Attackers stole OAuth tokens from Klue to breach LastPass Salesforce data on June 12, 2026. Nine orgs confirmed hit; Salesforce shut the Klue app June 17.

emanuel de almeida · read →
Illustration of the AryStinger botnet showing thousands of compromised legacy routers distributed around the globe, all linked into a covert network that attackers use for reconnaissance and as proxy nodes to relay malicious traffic
[Security] · Jun 21, 2026 · 17:23 UTC

AryStinger Botnet: 4,300 D-Link Routers Hijacked as Proxies

AryStinger botnet has hijacked 4,300+ D-Link and Linksys routers since March 12, 2026, using a zero-detection ELF payload to build a covert proxy and recon network.

emanuel de almeida · read →
Illustration of CVE-2026-20253 in Splunk Enterprise showing attackers abusing an unauthenticated PostgreSQL sidecar endpoint behind the web tier to gain remote code execution on vulnerable 10.x servers, with a CVSS 9.8 severity bar and a CISA KEV entry added on June 18, 2026 that gives federal agencies three days to patch
[Vulnerabilities] · Jun 21, 2026 · 17:05 UTC

CVE-2026-20253: Splunk Enterprise RCE Exploited

CVE-2026-20253: CVSS 9.8 unauthenticated RCE in Splunk Enterprise. CISA added it to KEV June 18, 2026, giving federal agencies 3 days to patch.

emanuel de almeida · read →
Illustration of attackers actively exploiting a medium-severity vulnerability in the Gravity SMTP WordPress plugin where an unauthenticated REST API endpoint exposes API keys, mail service credentials and full system configuration data to anyone who knows the URL
[Vulnerabilities] · Jun 19, 2026 · 21:38 UTC

CVE-2026-4020: Gravity SMTP Info Disclosure Hits 100K Sites

CVE-2026-4020 lets unauthenticated attackers pull 365 KB of JSON - API keys, DB details, system data - from 100K+ WordPress sites. 412 IPs hit it by June 1, 2026.

emanuel de almeida · read →
Windows troubleshooting themed image showing a user confused by garbled file names in the Recycle Bin delete dialog after installing the June 2026 Patch Tuesday update
[Tech] · Jun 19, 2026 · 17:26 UTC

KB5094126 Patch Tuesday Bug Breaks Recycle Bin Delete Dialogs

Microsoft's KB5094126 (June 9, 2026) breaks Recycle Bin delete dialogs on all Windows versions, showing $Rxxxxx filenames. No data loss; fix pending.

emanuel de almeida · read →
Illustration of an unauthenticated critical Splunk Enterprise RCE flaw added to CISA’s KEV catalog with a public proof of concept.
[Vulnerabilities] · Jun 19, 2026 · 05:00 UTC

CVE-2026-20253: Splunk Enterprise RCE Actively Exploited

CVE-2026-20253, a CVSS 9.8 unauthenticated RCE in Splunk Enterprise, hit CISA's KEV catalog June 18, 2026 - eight days after disclosure, with a public PoC already live.

emanuel de almeida · read →
Illustration of an ESET threat report on Gentlemen RaaS highlighting that the ransomware-as-a-service operation maintains eight in-house EDR killer variants and uses three additional third-party tools to disable endpoint protection, with a victim chart placing it second among ransomware groups in early 2026
[Security] · Jun 18, 2026 · 23:27 UTC

Ransomware Group Gentlemen Deploys Multi-EDR Killer Suite

Ransomware group Gentlemen confirms eight in-house EDR killer variants plus three third-party tools, ranking second for victims in early 2026 with 332 listings.

emanuel de almeida · read →
Illustration of the FortiBleed incident, where a massive cache of stolen credentials exposes Fortinet FortiGate VPN logins for 73,932 firewall URLs across 194 countries, showing leaked usernames and passwords mapped to corporate VPN gateways worldwide
[Security] · Jun 18, 2026 · 22:44 UTC

FortiBleed: 73,932 Fortinet VPN Credentials Exposed

FortiBleed exposed VPN and admin credentials for 73,932 FortiGate firewalls across 194 countries after attackers cracked SSL VPN hashes with a 45-GPU cluster. CVSS 9.1.

emanuel de almeida · read →
show