Security news & tech updates for sysadmins and IT pros
Cybersecurity advisories, CVE watch and the tech worth sharing, scored by trend and updated regularly, written for people who actually run infrastructure.
71 results

Klue OAuth Breach Exposes Salesforce Data - June 2026
Icarus stole OAuth tokens from Klue's backend on June 11, 2026, raiding Salesforce orgs of 500+ enterprise customers. Huntress confirms it was hit.

Broken Entra Access Controls Exposed FIFA World Cup Streams
A free FIFA agent sign-up gave any attacker admin access to all 78 World Cup 2026 RTMP stream keys via a broken Entra API - with no bug bounty to report it.

NGINX CVE-2026-42530 & CVE-2026-42055: F5 Critical Patches
F5 released out-of-band patches on June 18, 2026 for four NGINX flaws, including two CVSS 9.2 criticals affecting versions 1.13.10–1.31.1 that enable DoS or code execution.

RoguePlanet CVE-2026-50656: Defender Zero-Day Explained
Microsoft is developing a fix for CVE-2026-50656 RoguePlanet, a CVSS 7.8 Defender zero-day on fully patched Windows 10/11. No patch yet; allowlisting blocks it.

JetBrains Malicious Plugins Steal AI API Keys: 70K Installs
15 malicious JetBrains Marketplace plugins across 7 vendor accounts hit 70,000 installs, silently stealing OpenAI, DeepSeek, and SiliconFlow API keys.

CVE-2026-35273: Oracle PeopleSoft Zero-Day RCE Actively Exploited
CVSS 9.8 zero-day CVE-2026-35273 hit 300+ Oracle PeopleSoft instances before the June 10 patch. CISA orders federal remediation by July 3, 2026.

Rokarolla Android Malware Targets 217 Banking Apps
Rokarolla Android banking trojan wields 137 remote commands to steal PINs, intercept OTPs, and hijack crypto wallets across 217 targeted apps.

MSP Services for Swiss SMBs: What IT Pros Must Know
Swiss SMBs face ransomware in 88% of breaches. Here is what to demand from your MSP: sub-15-min P1 SLA, immutable backups, and nLPD-compliant data residency.

DragonForce Abuses Microsoft Teams TURN Servers for C2
DragonForce's Backdoor.Turn RAT tunnels C2 traffic via Microsoft Teams TURN relays over QUIC/UDP-443, evading detection for up to two months in a Dec 2025 U.S. attack.

CVE-2026-54420: CISA Orders LiteSpeed cPanel Patch
CISA added CVE-2026-54420 (CVSS 8.5) to its KEV catalog on June 15, 2026, setting a 3-day federal deadline to patch LiteSpeed cPanel plugin before 2.4.8.

FortiSandbox Critical Flaws Actively Exploited: Patch Now
CVE-2025-59718 (CVSS 9.8) and CVE-2025-59719 in Fortinet FortiSandbox are confirmed exploited in the wild. CISA added both to KEV. Patch immediately.

Anthropic Export Ban: 76 Security Execs Demand Reversal
76 cybersecurity executives from Adobe, Google, Nvidia signed an open letter urging Commerce to lift Anthropic Fable 5 and Mythos 5 export controls.

CVE-2026-20262: Cisco SD-WAN Root Bug Actively Exploited
Cisco patches CVE-2026-20262, a critical Catalyst SD-WAN Manager flaw granting root access. CISA issued Emergency Directive 26-03 as UAT-8616 exploits systems.

SearchLeak Vulnerability in Microsoft 365 Copilot Enables One-Click Data Theft
CVE-2026-42824 chains three flaws to exfiltrate emails, passwords, and documents via malicious URLs. Microsoft has patched server-side.

Conti Ransomware Developer Pleads Guilty: Ukrainian Faces 20 Years in Prison
Oleksii Lytvynenko admitted to building malware loaders for Conti, which extorted over $150 million from victims across 47 U.S. states and 31 countries.

Windows 11 KB5094126 June 2026: Key Fixes for Sysadmins
KB5094126 fixes HYPERVISOR_ERROR 0x20001 crashes and BitLocker recovery loops. Released June 9, 2026 for Windows 11 24H2/25H2.

Anthropic Blocks Fable 5 Globally After US Export Control Order
US Commerce Dept orders Anthropic to suspend Fable 5 and Mythos 5 globally on June 12, 2026, citing a reported jailbreak and foreign-national access risks.

npm 12 Blocks Install Scripts by Default: July 2026 Deadline
npm v12 disables dependency install scripts starting July 2026, affecting 2M+ packages. Developers must whitelist trusted packages via allowScripts in package.json.

June 2026 Patch Tuesday: 3 Zero-Days, 206 CVEs Fixed
Microsoft's largest-ever Patch Tuesday fixes 206 CVEs including three actively exploited zero-days. BitLocker bypass, Defender privilege escalation actively exploited.

CVE-2026-35273: Oracle PeopleSoft Zero-Day Exploited
CVE-2026-35273 enables unauthenticated RCE in Oracle PeopleSoft. ShinyHunter exploits this zero-day to steal HR/payroll data. Emergency patch available.