Security news & tech updates for sysadmins and IT pros
Cybersecurity advisories, CVE watch and the tech worth sharing, scored by trend and updated regularly, written for people who actually run infrastructure.
71 results

CVE-2026-20245: How Cisco SD-WAN Attackers Got Root
CVSS 7.8 zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN Manager lets authenticated attackers escalate to root - Mandiant confirms active exploitation across all deployment types.

Edgecution Malware: Edge Extension Deploys Ransomware
Edgecution abuses Edge Native Messaging to escape the browser sandbox, drop a Python backdoor, and trigger Payouts King ransomware with 4,096-bit RSA + 256-bit AES encryption.

OpenClaw Skills Bypass AI Scanners, Hit Supply Chain
Five ClawHub skills evaded VirusTotal and ClawScan for months - part of 341 malicious entries (12% of the registry) targeting OpenClaw users with macOS infostealers.

Operation Endgame 2026: Amadey and StealC Disrupted
Europol and partners seized 326 servers, 142 domains, and recovered 27 million credentials from 385,000+ systems in Operation Endgame's latest phase.

Cordyceps: GitHub Actions Flaws Risk Millions of Repos
Cordyceps flaws in GitHub Actions exposed 300+ repos - including Microsoft and Google - to credential theft and supply-chain poisoning. Here is what to fix.

UniFi OS CVSS 10.0 Flaws Actively Exploited - Patch Now
Three CVSS 10.0 flaws in Ubiquiti UniFi OS let unauthenticated attackers hijack devices. CISA added them to KEV on June 23, 2026. Patch to UniFi OS 5.1.12 before the June 26, 2026 federal deadline.

Cisco Unified CM CVE-2026-20230 SSRF: Active Exploitation Reported
CVE-2026-20230, a CVSS 8.6 SSRF flaw in Cisco Unified CM, carries a Critical rating due to root privilege escalation risk. Patch to 14SU6 or disable WebDialer now. No CISA KEV listing yet.

KB5095093: Windows 11 Point-in-Time Restore & Office Bug
KB5095093 (June 23, 2026) adds VSS snapshots covering 72 hours on drives 200 GB+ and breaks OLE automation for Office on 24H2/25H2 (build 26100.8737).

macOS ClickFix: Terminal Commands Silently Drop Infostealers
macOS ClickFix campaigns trick users into pasting Terminal commands that silently install infostealers, bypassing Gatekeeper on managed and personal Macs alike.

Windows 11 26H2: What IT Admins Need to Know
Microsoft confirmed Windows 11 26H2 on June 19, 2026 for Fall 2026 release. Devices on 24H2 or 25H2 upgrade via a ~200 KB enablement package, not a full OS reinstall.

WhatsApp VBScript Malware: How Attackers Hijack Windows PCs
WhatsApp VBScript malware is actively targeting Windows PCs across 11 countries: attackers send .vbs files that hijack systems via WSH. Here is how to block it now.

FFmpeg CVE-2026-8461 (PixelSmash): RCE via Media Files
A heap out-of-bounds write in FFmpeg's MagicYUV decoder scores CVSS 8.8 and hits 9+ apps including Jellyfin and Nextcloud. Patch to FFmpeg 8.1.2 now.

Klue OAuth Supply Chain Attack Hits LastPass Salesforce Data
Attackers stole OAuth tokens from Klue to breach LastPass Salesforce data on June 12, 2026. Nine orgs confirmed hit; Salesforce shut the Klue app June 17.

AryStinger Botnet: 4,300 D-Link Routers Hijacked as Proxies
AryStinger botnet has hijacked 4,300+ D-Link and Linksys routers since March 12, 2026, using a zero-detection ELF payload to build a covert proxy and recon network.

CVE-2026-20253: Splunk Enterprise RCE Exploited
CVE-2026-20253: CVSS 9.8 unauthenticated RCE in Splunk Enterprise. CISA added it to KEV June 18, 2026, giving federal agencies 3 days to patch.

CVE-2026-4020: Gravity SMTP Info Disclosure Hits 100K Sites
CVE-2026-4020 lets unauthenticated attackers pull 365 KB of JSON - API keys, DB details, system data - from 100K+ WordPress sites. 412 IPs hit it by June 1, 2026.

KB5094126 Patch Tuesday Bug Breaks Recycle Bin Delete Dialogs
Microsoft's KB5094126 (June 9, 2026) breaks Recycle Bin delete dialogs on all Windows versions, showing $Rxxxxx filenames. No data loss; fix pending.

CVE-2026-20253: Splunk Enterprise RCE Actively Exploited
CVE-2026-20253, a CVSS 9.8 unauthenticated RCE in Splunk Enterprise, hit CISA's KEV catalog June 18, 2026 - eight days after disclosure, with a public PoC already live.

Ransomware Group Gentlemen Deploys Multi-EDR Killer Suite
Ransomware group Gentlemen confirms eight in-house EDR killer variants plus three third-party tools, ranking second for victims in early 2026 with 332 listings.

FortiBleed: 73,932 Fortinet VPN Credentials Exposed
FortiBleed exposed VPN and admin credentials for 73,932 FortiGate firewalls across 194 countries after attackers cracked SSL VPN hashes with a 45-GPU cluster. CVSS 9.1.