NAVANEM

Security news & tech updates for sysadmins and IT pros

Cybersecurity advisories, CVE watch and the tech worth sharing, scored by trend and updated regularly, written for people who actually run infrastructure.

71stories
hourlyupdated
8sources

71 results

Cloud security themed image showing a central SaaS platform leaking OAuth tokens to an attacker, who then opens doors into connected Salesforce orgs as part of an extortion campaign
[Security] · Jun 18, 2026 · 21:49 UTC

Klue OAuth Breach Exposes Salesforce Data - June 2026

Icarus stole OAuth tokens from Klue's backend on June 11, 2026, raiding Salesforce orgs of 500+ enterprise customers. Huntress confirms it was hit.

emanuel de almeida · read →
Broadcast security themed image showing a World Cup control room, a public-facing agent portal and a warning badge over a streaming management dashboard representing missing role-based access controls
[Security] · Jun 18, 2026 · 21:04 UTC

Broken Entra Access Controls Exposed FIFA World Cup Streams

A free FIFA agent sign-up gave any attacker admin access to all 78 World Cup 2026 RTMP stream keys via a broken Entra API - with no bug bounty to report it.

emanuel de almeida · read →
Web security themed image showing NGINX servers receiving F5 critical security updates for CVE-2026-42530 and CVE-2026-42055
[Vulnerabilities] · Jun 18, 2026 · 12:29 UTC

NGINX CVE-2026-42530 & CVE-2026-42055: F5 Critical Patches

F5 released out-of-band patches on June 18, 2026 for four NGINX flaws, including two CVSS 9.2 criticals affecting versions 1.13.10–1.31.1 that enable DoS or code execution.

emanuel de almeida · read →
Threat intelligence themed image showing the Defender shield cracked by the RoguePlanet CVE-2026-50656 privilege escalation flaw
[Vulnerabilities] · Jun 18, 2026 · 12:12 UTC

RoguePlanet CVE-2026-50656: Defender Zero-Day Explained

Microsoft is developing a fix for CVE-2026-50656 RoguePlanet, a CVSS 7.8 Defender zero-day on fully patched Windows 10/11. No patch yet; allowlisting blocks it.

emanuel de almeida · read →
Developer security themed image showing a plugin supply-chain attack in a JetBrains-like IDE targeting AI API keys
[Security] · Jun 17, 2026 · 00:42 UTC

JetBrains Malicious Plugins Steal AI API Keys: 70K Installs

15 malicious JetBrains Marketplace plugins across 7 vendor accounts hit 70,000 installs, silently stealing OpenAI, DeepSeek, and SiliconFlow API keys.

emanuel de almeida · read →
Cybersecurity themed image depicting active exploitation of CVE-2026-35273 against Oracle PeopleSoft systems by threat actors targeting higher-education organizations
[Vulnerabilities] · Jun 16, 2026 · 23:05 UTC

CVE-2026-35273: Oracle PeopleSoft Zero-Day RCE Actively Exploited

CVSS 9.8 zero-day CVE-2026-35273 hit 300+ Oracle PeopleSoft instances before the June 10 patch. CISA orders federal remediation by July 3, 2026.

emanuel de almeida · read →
Mobile threat intelligence themed image showing an Android phone infected with Rokarolla and attacking multiple banking and crypto apps
[Security] · Jun 16, 2026 · 21:46 UTC

Rokarolla Android Malware Targets 217 Banking Apps

Rokarolla Android banking trojan wields 137 remote commands to steal PINs, intercept OTPs, and hijack crypto wallets across 217 targeted apps.

emanuel de almeida · read →
Consulting themed image showing MSP offerings mapped to the needs of Swiss SMEs and their in-house IT teams
[Tech] · Jun 16, 2026 · 21:32 UTC

MSP Services for Swiss SMBs: What IT Pros Must Know

Swiss SMBs face ransomware in 88% of breaches. Here is what to demand from your MSP: sub-15-min P1 SLA, immutable backups, and nLPD-compliant data residency.

emanuel de almeida · read →
Threat intelligence themed image showing ransomware operators abusing Teams TURN relays to mask malicious C2 traffic
[Security] · Jun 16, 2026 · 20:32 UTC

DragonForce Abuses Microsoft Teams TURN Servers for C2

DragonForce's Backdoor.Turn RAT tunnels C2 traffic via Microsoft Teams TURN relays over QUIC/UDP-443, evading detection for up to two months in a Dec 2025 U.S. attack.

emanuel de almeida · read →
Illustration of CISA ordering urgent patching of the LiteSpeed cPanel CVE-2026-54420 symlink vulnerability
[Vulnerabilities] · Jun 16, 2026 · 19:49 UTC

CVE-2026-54420: CISA Orders LiteSpeed cPanel Patch

CISA added CVE-2026-54420 (CVSS 8.5) to its KEV catalog on June 15, 2026, setting a 3-day federal deadline to patch LiteSpeed cPanel plugin before 2.4.8.

emanuel de almeida · read →
Illustration of critical Fortinet FortiSandbox vulnerabilities being actively exploited against a sandbox appliance
[Vulnerabilities] · Jun 16, 2026 · 17:34 UTC

FortiSandbox Critical Flaws Actively Exploited: Patch Now

CVE-2025-59718 (CVSS 9.8) and CVE-2025-59719 in Fortinet FortiSandbox are confirmed exploited in the wild. CISA added both to KEV. Patch immediately.

emanuel de almeida · read →
AI policy themed image showing Anthropic’s top models restricted for foreign users and security executives calling for the ban to be lifted
[Security] · Jun 15, 2026 · 20:19 UTC

Anthropic Export Ban: 76 Security Execs Demand Reversal

76 cybersecurity executives from Adobe, Google, Nvidia signed an open letter urging Commerce to lift Anthropic Fable 5 and Mythos 5 export controls.

emanuel de almeida · read →
Visualization of an active exploit targeting a critical Cisco SD-WAN vulnerability
[Vulnerabilities] · Jun 15, 2026 · 17:55 UTC

CVE-2026-20262: Cisco SD-WAN Root Bug Actively Exploited

Cisco patches CVE-2026-20262, a critical Catalyst SD-WAN Manager flaw granting root access. CISA issued Emergency Directive 26-03 as UAT-8616 exploits systems.

emanuel de almeida · read →
Microsoft 365 Copilot interface being abused via malicious URLs to steal sensitive data
[Vulnerabilities] · Jun 15, 2026 · 15:27 UTC

SearchLeak Vulnerability in Microsoft 365 Copilot Enables One-Click Data Theft

CVE-2026-42824 chains three flaws to exfiltrate emails, passwords, and documents via malicious URLs. Microsoft has patched server-side.

emanuel de almeida · read →
Illustration of Conti ransomware developer Oleksii Lytvynenko pleading guilty and facing up to 20 years in prison
[Security] · Jun 15, 2026 · 13:53 UTC

Conti Ransomware Developer Pleads Guilty: Ukrainian Faces 20 Years in Prison

Oleksii Lytvynenko admitted to building malware loaders for Conti, which extorted over $150 million from victims across 47 U.S. states and 31 countries.

emanuel de almeida · read →
Visualization of a Windows 11 24H2/25H2 cumulative update resolving virtualization-related HYPERVISOR_ERROR 0x20001 crashes and stopping BitLocker from repeatedly asking for the recovery key on every boot
[Tech] · Jun 13, 2026 · 21:13 UTC

Windows 11 KB5094126 June 2026: Key Fixes for Sysadmins

KB5094126 fixes HYPERVISOR_ERROR 0x20001 crashes and BitLocker recovery loops. Released June 9, 2026 for Windows 11 24H2/25H2.

emanuel de almeida · read →
AI governance themed image showing a powerful model being disconnected from a global user base by a red export control stamp referencing national security and jailbreak risks
[Security] · Jun 13, 2026 · 21:09 UTC

Anthropic Blocks Fable 5 Globally After US Export Control Order

US Commerce Dept orders Anthropic to suspend Fable 5 and Mythos 5 globally on June 12, 2026, citing a reported jailbreak and foreign-national access risks.

emanuel de almeida · read →
Visualization of a JavaScript project where npm v12 prevents automatic execution of dependency lifecycle scripts and Git or remote URL dependencies unless developers opt in using npm approve-scripts and an allowScripts whitelist
[Security] · Jun 13, 2026 · 19:24 UTC

npm 12 Blocks Install Scripts by Default: July 2026 Deadline

npm v12 disables dependency install scripts starting July 2026, affecting 2M+ packages. Developers must whitelist trusted packages via allowScripts in package.json.

emanuel de almeida · read →
Windows security update themed image showing a long CVE list with three zero-days in red, alongside icons for BitLocker disk encryption and the Defender shield representing actively exploited vulnerabilities patched in June 2026
[Security] · Jun 12, 2026 · 22:00 UTC

June 2026 Patch Tuesday: 3 Zero-Days, 206 CVEs Fixed

Microsoft's largest-ever Patch Tuesday fixes 206 CVEs including three actively exploited zero-days. BitLocker bypass, Defender privilege escalation actively exploited.

emanuel de almeida · read →
This image represents the risk that a single unauthenticated RCE can pose in ERP platforms like PeopleSoft, especially when HR and payroll systems are involved, underlining how quickly threat actors exploited CVE-2026-35273 and why immediate patching, log review and hardening of PSEMHUB endpoints are now critical for affected customers.
[Vulnerabilities] · Jun 12, 2026 · 19:54 UTC

CVE-2026-35273: Oracle PeopleSoft Zero-Day Exploited

CVE-2026-35273 enables unauthenticated RCE in Oracle PeopleSoft. ShinyHunter exploits this zero-day to steal HR/payroll data. Emergency patch available.

emanuel de almeida · read →
show